CVE intelligence

CVE-2026-86197

Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav

Published 2026-09-05 · CVSS

medium

NIST record