{"id":"CVE-2026-75834","aliases":["GHSA-q2j8-x8hf-63ch"],"url":"https://o3.security/vulnerability/CVE-2026-75834","summary":"Grav before 2.0.14 Stored XSS via Invalid UTF-8 Byte","details":"Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). All XSS detection patterns use the PCRE /u (UTF-8) modifier, so a single invalid UTF-8 byte anywhere in page content causes preg_match() to return false for every pattern, silently bypassing the save-time XSS safety gate (Validation::checkSafety()). An authenticated attacker with page-edit permissions (without the security.xss_whitelist privilege) can store malicious JavaScript that executes in the browser of a visitor who views the affected page.","published":"2026-08-18T11:19:45.094Z","modified":"2026-09-10T03:31:06.263533689Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"getgrav/grav","fixedVersion":"2.0.14"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75834.json"},{"type":"ADVISORY","url":"https://github.com/getgrav/grav/security/advisories/GHSA-q2j8-x8hf-63ch"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75834"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/grav-before-stored-xss-via-invalid-utf-8-byte"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:31:06.263533689Z"}}