CVE-2026-86197 | GetGrav up to 2.0.19 Twig Sandbox Policy Grav/Common/Assets addJs cross site scripting

SecurityVulns

A vulnerability was found in GetGrav Grav up to 2.0.19 and classified as problematic. The impacted element is the function addJs of the file Grav/Common/Assets of the component Twig Sandbox Policy. Executing a manipulation can lead to cross site scripting.

This vulnerability is registered as CVE-2026-86197. It is possible to launch the attack remotely. No exploit is available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More