
CVE-2026-61454 The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/… https://www.cve.org/CVERecord?id=CVE-2026-61454
Post summary
The CVE reveals that the Grav Admin2 plugin (pre‑2.0.4) exposes its configuration through a global JavaScript variable within the admin bootstrap page.


