A vulnerability, which was classified as problematic, has been found in getgrav grav up to 6.2.1. Affected by this issue is some unknown functionality of the component shortcode-core attribute handlers. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-64628. The attack may be initiated remotely. There is no available exploit.