Authenticated users can achieve remote code execution in Grav CMS versions prior to 2.0.13 by exploiting improper input validation in the Flex Objects plugin to upload and execute arbitrary PHP files.
Grav CMS +2
web-application-vulnerability
rce
ssti
cms
privilege-escalation
web-application
remote-code-execution
cve-2026-75827
2r
6t
1c
updated