CVE-2026-11982EPSS p38.6%

CVE-2026-11982CVE-2026-11982

Description

Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site scripting (XSS) vulnerability in the Admin2 Pages API save flow.

Scoring

EPSS0.47% probability of exploitation · percentile 38.6% · 2026-08-03T12:00:16Z
Last modified2026-06-18
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.