{"id":"CVE-2026-72832","aliases":["GHSA-269c-h76q-8cxw"],"url":"https://o3.security/vulnerability/CVE-2026-72832","summary":"Grav before 2.0.12 Stored XSS via quoted-attribute bypass","details":"Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). The event-handler scan is anchored at `<` and uses `[^>]*?`, which cannot cross the first literal `>`; when a `>` appears inside a quoted attribute value the browser keeps the tag open and parses a subsequent event handler (e.g. onerror), so the detector and browser disagree. A page editor without admin.super privileges can save page content such as `<img src=x title=\">\" onerror=alert(document.domain)>`, which is accepted, stored, and executed in the site origin when any visitor (including unauthenticated users) views the page. Fixed in 2.0.13.","published":"2026-08-14T11:35:38.484Z","modified":"2026-09-10T03:31:01.567165617Z","cvss":null,"epss":{"score":0.0018,"percentile":0.07829,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":{"url":"https://github.com/getgrav/grav/commit/ad9709f865b09b68798fb1ac375b484a8cc1d892","label":"getgrav/grav@ad9709f"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72832.json"},{"type":"ADVISORY","url":"https://github.com/getgrav/grav/security/advisories/GHSA-269c-h76q-8cxw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72832"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/grav-before-stored-xss-via-quoted-attribute-bypass"},{"type":"FIX","url":"https://github.com/getgrav/grav/commit/ad9709f865b09b68798fb1ac375b484a8cc1d892"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:31:01.567165617Z"}}