Skip to content
Grav 2.1 is out: every page speaks Markdown. Read the announcement →

Has the core and themes been tested for XSS attacks?

Started by Vikas 9 years ago · 4 replies · 897 views
9 years ago

My client's wordpress website was recently hit hard by an XSS attack. Since I am not doing a lot of maintenance these days, I would like to move to grav. I was just wondering if grav is XSS safe and what kind of penetration testing has been done on it?

9 years ago

@vikas:
XSS

what is a XSS attack, iam still new to this

9 years ago

We've had a few XSS issues reported over the past couple of years, and those have all been promptly fixed. To be honest, most XSS issues reported have required a valid admin login, which really means the user already has complete access to the content anyway, so the XSS vector was not really a realistic vulnerability.

👍 1
9 years ago

@rhuk:
We’ve had a few XSS issues reported over the past couple of years, and those have all been promptly fixed.

Cheers for the quick reply Andy. I came across this in the meantime. Looking forward to working with Grav.

Suggested topics

Topic Participants Replies Views Activity
Support · by Marcel, 5 days ago
0 83 5 days ago
Support · by JakobDB, 6 days ago
1 89 5 days ago
Support · by ramenos, 7 days ago
3 103 6 days ago
Support · by gravinator, 2 weeks ago
3 228 7 days ago
Support · by Roger Parkinson, 2 weeks ago
3 308 2 weeks ago