A AegiFlow
MEDIUMCVSS 5.1

CVE-2026-85600

CVE-2026-85600 updated by NVD

Modified
2026-09-10
Sources
nvd

Summary

Grav Admin (getgrav/grav-plugin-admin2) versions , ", or ', allowing an attacker to register a username containing an HTML payload. When an administrator views a UI surface that renders the username through tHtml()—such as the two-factor force-disable confirmation prompt or the 'page is locked' editor notice—the payload executes in their authenticated session. Fixed in 2.0.21.

References

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.