Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.
| Software | From | Fixed in |
|---|---|---|
| getgrav / grav_cms | - | 1.6.15.x |
getgrav / grav
|
- | 1.7.0-beta.8 |