Product
high
advisory
Grav CMS Path Traversal in MediaUploadTrait Leading to Arbitrary File Deletion
3 TTPs 1 CVEAn authenticated path traversal vulnerability in Grav CMS's MediaUploadTrait allows users with media management permissions to delete arbitrary files on the server by providing crafted file paths.
Grav CMS +1
grav
cms
path-traversal
cve-2026-72695
file-disclosure
web-application
3t
1c
high
advisory
Path Traversal Vulnerability in Grav CMS ImageMedium Class
1 rule 2 TTPs 1 CVEGrav CMS 2.0.10 is vulnerable to path traversal in the ImageMedium::watermark() method, allowing unauthenticated attackers to disclose arbitrary image files by traversing outside the media sandbox.
Grav CMS +1
web-vulnerability
twig
information-disclosure
1r
2t
1c
updated