{"id":"CVE-2021-3920","details":"grav-plugin-admin is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","modified":"2026-07-09T01:07:12.268494Z","published":"2021-11-19T13:15:09.830Z","references":[{"type":"FIX","url":"https://github.com/getgrav/grav-plugin-admin/commit/6463135bf046d8131189c163158cd5db8f7a9675"},{"type":"EVIDENCE","url":"https://huntr.dev/bounties/ab564760-90c6-4e1d-80c2-852f45034cd1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/getgrav/grav-plugin-admin","events":[{"introduced":"0"},{"fixed":"21ba0821f09936861176e7293d4fb708c8f6a870"},{"fixed":"6463135bf046d8131189c163158cd5db8f7a9675"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.10.25"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:getgrav:grav-plugin-admin:*:*:*:*:*:*:*:*"}}],"versions":["1.10.24","1.10.23","1.10.22","1.10.21","1.10.20","1.10.19","1.10.18","1.10.17","1.10.16","1.10.15","1.10.14","1.10.13","1.10.12","1.10.10","1.10.9","1.10.8","1.10.7","1.10.6","1.10.5","1.10.4","1.10.3","1.10.2","1.10.1","1.10.0","1.9.19","1.10.0-rc.20","1.9.18","1.10.0-rc.19","1.10.0-rc.18","1.9.17","1.10.0-rc.17","1.9.16","1.10.0-rc.16","1.9.15","1.10.0-rc.15","1.10.0-rc.14","1.10.0-rc.13","1.10.0-rc.12","1.9.14","1.10.0-rc.11","1.10.0-rc.10","1.10.0-rc.9","1.9.13","1.10.0-rc.8","1.10.0-rc.7","1.9.12","1.10.0-rc.6","1.10.0-rc.5","1.10.0-rc.4","1.10.0-rc.3","1.10.0-rc.2","1.10.0-rc.1","1.9.10","1.10.0-beta.10","1.10.0-beta.9","1.10.0-beta.8","1.9.9","1.10.0-beta.7","1.10.0-beta.6","1.9.8","1.10.0-beta.5","1.9.7","1.10.0-beta.4","1.10.0-beta.3","1.10.0-beta.2","1.9.6","1.10.0-beta.1","1.9.5","1.9.4","1.9.3","1.9.2","1.9.1","1.9.0","1.8.20","1.8.19","1.8.18","1.8.17","1.8.16","1.8.15","1.8.14","1.8.13","1.8.12","1.8.11","1.8.10","1.8.9","1.8.8","1.8.7","1.8.6","1.8.5","1.8.4","1.8.3","1.8.2","1.8.1","1.8.0","1.7.4","1.7.3","1.7.2","1.7.1","1.7.0","1.6.7","1.6.6","1.6.5","1.6.4","1.6.3","1.6.2","1.6.1","1.6.0","1.5.2","1.5.1","1.5.0","1.4.2","1.4.1","1.4.0","1.3.3","1.3.2","1.3.1","1.3.0","1.2.14","1.2.13","1.2.12","1.2.5-rc.4","1.2.5-rc.3","1.2.5-rc.2","1.2.5-rc.1","1.2.0-rc.2","1.2.0-rc.1","1.1.0-rc.4","1.1.0-rc.3","1.1.0-rc.2","1.1.0-rc.1","1.1.0-beta.5","1.1.0-beta.4","1.1.0-beta.3","1.1.0-beta.2","1.1.0-beta.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3920.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}