Skip to main content
Vulnerability Database/CVE-2026-100673

CVE-2026-100673: Grav Data Manager Plugin XSS Vulnerability

CVE-2026-100673 is a stored cross-site scripting vulnerability in Grav Data Manager plugin that allows unauthenticated attackers to execute JavaScript in administrator sessions. This article covers technical details, affected versions, impact, and mitigation steps.

Published:

CVE-2026-100673 Overview

CVE-2026-100673 is a stored cross-site scripting (XSS) vulnerability in the Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4. The plugin renders stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's raw filter. An unauthenticated attacker can submit a front-end form that saves to user/data, storing an HTML payload that executes in the browser of an administrator who later opens the entry in the classic admin panel. The injected JavaScript runs with the administrator's session, origin, and CSRF token. Sites using the Grav 2.0 Admin Next interface are not affected.

Critical Impact

Unauthenticated attackers can achieve administrator-level code execution in the admin panel session, enabling account takeover and site compromise through stored XSS [CWE-79].

Affected Products

  • Grav Data Manager plugin versions 1.0.1 through 1.4.4
  • Grav CMS installations using the classic admin panel with Data Manager enabled
  • Not affected: Grav 2.0 Admin Next interface

Discovery Timeline

  • 2026-09-26 - CVE-2026-100673 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-100673

Vulnerability Analysis

The Data Manager plugin's item-detail Twig template renders user-submitted field values through the raw filter, which instructs Twig to emit output without HTML escaping. In some code paths the template calls striptags('<br>') before the raw filter, intending to permit only line-break tags. PHP's underlying strip_tags() function preserves allowed tags together with their attributes, so an attacker can submit <br onmouseover="..."> or similar constructs that survive sanitization and execute JavaScript.

Stored payloads execute when an administrator opens the affected entry in the classic admin panel. List-type fields such as checkbox or multi-select values trigger execution without further interaction. Ordinary text fields execute on hover. The injected script runs with the administrator's privileges, cookies, and CSRF token, enabling arbitrary admin API calls.

Root Cause

The root cause is improper neutralization of input during web page generation [CWE-79]. The template combines Twig's raw filter with a PHP strip_tags() allow-list that fails to strip HTML attributes on permitted tags. This creates an attribute-injection sink in the item-detail view that stores and later renders attacker-controlled markup.

Attack Vector

The attack vector is network-based and requires no attacker authentication. An attacker locates a front-end form whose submissions are persisted to user/data through the Data Manager plugin. The attacker submits a payload crafted to bypass strip_tags('<br>') by embedding event handler attributes on a permitted tag. The payload persists in the data store and detonates when any administrator views the entry in the classic admin panel.

See the GitHub Security Advisory GHSA-863q-9v8v-m9fv and the VulnCheck Advisory for Grav XSS for additional technical detail.

Detection Methods for CVE-2026-100673

Indicators of Compromise

  • Entries in user/data/ containing HTML tags with event handler attributes such as onmouseover=, onerror=, onclick=, or onload=.
  • Unexpected administrator actions such as new user creation, plugin installation, or configuration changes shortly after an admin opened a Data Manager entry.
  • Admin-session HTTP requests originating from the admin panel that invoke privileged endpoints without a corresponding admin UI click.

Detection Strategies

  • Grep the user/data/ directory for suspicious attributes: grep -rEi 'on[a-z]+\s*=' user/data/.
  • Review web server access logs for unauthenticated POST requests to front-end form endpoints followed later by admin-authenticated requests to Data Manager views.
  • Audit the installed version of getgrav/grav-plugin-datamanager and flag any instance below 1.4.5.

Monitoring Recommendations

  • Alert on administrator sessions that issue privileged API calls within seconds of loading a Data Manager item-detail page.
  • Monitor file-integrity changes to user/accounts/, installed plugin directories, and Grav configuration files.
  • Ingest Grav admin and web server logs into a centralized SIEM and correlate form-submission events with subsequent admin activity.

How to Mitigate CVE-2026-100673

Immediate Actions Required

  • Upgrade the Grav Data Manager plugin to version 1.4.5 or later on all affected sites.
  • Rotate administrator credentials and invalidate active admin sessions after patching to contain potential prior compromise.
  • Review user/data/ entries for stored payloads and remove or sanitize any suspicious records before administrators access them.

Patch Information

The issue is fixed in Grav Data Manager 1.4.5. Update through the Grav admin plugin manager or via Composer by pinning getgrav/grav-plugin-datamanager to ^1.4.5. Refer to the GitHub Security Advisory GHSA-863q-9v8v-m9fv for the authoritative fix reference.

Workarounds

  • Disable the Data Manager plugin until the upgrade to 1.4.5 is complete.
  • Restrict or disable front-end forms that persist submissions to user/data to prevent new payload storage.
  • Switch to the Grav 2.0 Admin Next interface, which renders the same data through a separate, correctly escaping code path and is not affected.
bash
# Upgrade the Data Manager plugin via the Grav CLI
bin/gpm update data-manager

# Or pin the fixed version with Composer
composer require getgrav/grav-plugin-datamanager:^1.4.5

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.