OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100673

HIGH · CVSS 8.2 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The Grav Data Manager plugin for Java, versions 1.0.1 through 1.4.4, is vulnerable due to improper escaping of stored data entries, allowing unauthenticated users to inject malicious HTML and JavaScript payloads. This vulnerability can lead to remote code execution in the context of an administrator's session when they view the compromised entries, posing a significant risk to site integrity and security. Organizations using affected versions of the Grav Data Manager should prioritize upgrading to version 1.4.5 or later to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100673
Severity
HIGH
CVSS
8.2
EPSS
0.29%
Java

Original NVD Description

The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('<br>') call that PHP's strip_tags() bypasses by preserving allowed tags together with their attributes. An unauthenticated visitor who submits a front-end form whose submissions are saved to user/data can store an HTML payload that executes as JavaScript in the session and origin of an administrator who later opens that entry in the classic admin panel, running with that administrator's privileges and CSRF token. Execution occurs without further interaction for list values (such as checkbox or multi-select fields) and on hover for ordinary text fields. Sites using the Grav 2.0 Admin Next interface are not affected, because it renders the same data through a separate, correctly escaping code path. The issue is fixed in Data Manager 1.4.5.