
🚨 HIGH SEVERITY: CVE-2026-42612 CVSS 8.5 - Stored XSS in Grav CMS (<2.0.0-beta.2) allows publisher accounts to execute arbitrary JavaScript via unquoted HTML event attributes. ✅ Update to 2.0.0-beta.2 #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/gwLfPob0dp
Post summary
A high‑severity stored XSS flaw (CVE‑2026‑42612) affects Grav CMS versions below 2.0.0‑beta.2, but a patch (2.0.0‑beta.2) is available to mitigate the risk.


