ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-37256”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-37256
Published
2026-06-25
CVSS:
5.1
ShadowTrackr CVSS:
1.2
Summary:
Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities can inject malicious scripts to execute arbitrary code and install malicious plugins for system access.