An API key scope-cap bypass in the Grav API plugin allows attackers with restricted keys to execute server-side templates via Server-Side Template Injection.
grav-plugin-api +2
web-vulnerability
rce
ssti
grav-cms
web-application-vulnerability
cve-2026-75829
1r
3t
1c
updated