Skip to content
Threat Feed

Vendor

GetGrav

17 briefs RSS
high advisory

Grav CMS Path Traversal in MediaUploadTrait Leading to Arbitrary File Deletion

An authenticated path traversal vulnerability in Grav CMS's MediaUploadTrait allows users with media management permissions to delete arbitrary files on the server by providing crafted file paths.

Grav CMS +1 grav cms path-traversal cve-2026-72695 file-disclosure web-application
3t 1c
high advisory

Grav Privilege Escalation via Group Blueprint ACL Bypass

A missing 'security@' guard in Grav's group blueprint allows an 'admin.users' operator to escalate privileges to 'admin.super' by modifying group access configurations.

Grav +2 privilege-escalation cms vulnerability web-application-vulnerability path-traversal cve-2026-74907 twig security-misconfiguration
1r 3t 1c
high advisory

Remote Code Execution in Grav via Twig sort filter

Grav versions 2.0.17 and earlier contain a remote code execution vulnerability in the Twig sort filter that allows authenticated users with page-write permissions to execute arbitrary PHP code.

Grav remote-code-execution web-application php
1t 1c
high advisory

CVE-2026-72700: Timing Vulnerability in Grav Login Plugin

The Grav login plugin for Composer is vulnerable to token-recovery via timing attacks due to non-constant-time string comparisons and a lack of rate limiting on password reset endpoints.

grav-plugin-login credential-access vulnerability web-application
1t 1c
high advisory

Remote Code Execution in Grav Email Plugin via Twig Injection

The Grav Email plugin version 4.2.1 and below allows authenticated attackers to achieve remote code execution by injecting malicious Twig expressions into form processing parameters.

grav-plugin-email
1t 1c
high advisory

Authorization Bypass in Grav Flex Objects Plugin

An authorization bypass vulnerability (CVE-2026-56707) in Grav Flex Objects plugin versions 1.4.0 through 1.4.7 allows authenticated users with page-edit privileges to exfiltrate sensitive data by rendering unauthorized Flex collections via shortcodes.

Flex Objects plugin web-security cms data-exposure
1t 1c
high advisory

Remote Code Execution in Grav CMS Flex Objects Plugin

Authenticated users can achieve remote code execution in Grav CMS versions prior to 2.0.13 by exploiting improper input validation in the Flex Objects plugin to upload and execute arbitrary PHP files.

Grav CMS +2 web-application-vulnerability rce ssti cms privilege-escalation web-application remote-code-execution cve-2026-75827
2r 6t 1c updated
critical advisory

Remote Code Execution in Grav API Plugin via Privilege Escalation

The Grav API plugin before version 1.0.13 fails to enforce API key scope restrictions in ConfigController, enabling remote code execution via injected scheduler commands.

Grav API plugin remote-code-execution privilege-escalation web-application-vulnerability
1r 3t 1c updated
high advisory

Authentication Scope Bypass in Grav API Plugin Leading to RCE

An API key scope-cap bypass in the Grav API plugin allows attackers with restricted keys to execute server-side templates via Server-Side Template Injection.

grav-plugin-api +2 web-vulnerability rce ssti grav-cms web-application-vulnerability cve-2026-75829
1r 3t 1c updated
high advisory

Grav API Plugin Vulnerability Exposes JWT Access Tokens via URL Parameter

The Grav API plugin (getgrav/grav-plugin-api) before version 1.0.0-rc.16 is vulnerable to sensitive information exposure, accepting JWT access tokens via the '?token=' URL query parameter, causing these tokens to be logged in web server access logs, browser history, and potentially leaked through Referer headers, proxy, or CDN logs, which allows an attacker to gain unauthorized API access, read configuration and user data, create new admin accounts, modify system settings, and delete pages.

Grav API plugin +1 vulnerability web api jwt information-exposure grav
1r 6t 1c
high threat

CVE-2026-62234: Grav SSRF Vulnerability via Unrestricted cURL Protocols in Webhooks

An authenticated user with `api.webhooks.write` permissions can exploit CVE-2026-62234, a Server-Side Request Forgery (SSRF) vulnerability in Grav before version 2.0.4, by creating webhooks with unrestricted cURL protocols like `file://`, `dict://`, or `gopher://` to read local files, access process information, and pivot to internal services.

exploited Grav ssrf web-application cve vulnerability
5t 1c
high advisory

Grav Plugin API Privilege Escalation via Authorization Bypass (CVE-2026-62233)

A privilege escalation vulnerability (CVE-2026-62233) in grav-plugin-api before version 1.0.6 allows non-super api.users.write managers to bypass authorization checks on administrative API endpoints, enabling the creation of super-admin API keys or disabling super-admin Two-Factor Authentication (2FA), leading to full Grav instance takeover.

grav-plugin-api privilege-escalation vulnerability grav
1t 1c
high advisory

Grav Form Plugin Arbitrary File Write Vulnerability (CVE-2026-61873)

Grav before version 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, allowing attackers to bypass path traversal validation via Twig template processing and write PHP webshells for remote code execution.

Grav arbitrary-file-write rce web-vulnerability cms path-traversal
1r 3t 1c
high advisory

CVE-2026-58656 - Grav API Plugin Cross-Origin Authentication Bypass and Account Takeover

A critical vulnerability, CVE-2026-58656, in the Grav API plugin before v1.0.0-rc.16 allows unauthenticated attackers to perform fully authenticated cross-origin API requests by leveraging leaked JWT tokens via the `?token=` URL query parameter and the `Access-Control-Allow-Origin: *` response header, potentially leading to persistent backdoor super-admin accounts and sensitive data exfiltration.

Grav API plugin grav api-plugin jwt cors remote-code-execution web-vulnerability
1r 3t 1c
critical advisory

Grav CMS API Blueprint Upload Privilege Escalation

A low-privileged authenticated API user with `api.media.write` can abuse `/api/v1/blueprint-upload` in Grav CMS to write an arbitrary YAML file into `user/accounts/`, enabling creation of a super-admin account and leading to full administrative compromise of the Grav API.

grav gravcms privilege-escalation yaml-injection
2r 1t
high advisory

Grav File Cache Insecure Deserialization Vulnerability

Grav versions 1.7.44 through 1.7.49.5 are vulnerable to insecure deserialization in the File Cache component, where the `unserialize` function with `allowed_classes => true` can lead to arbitrary code execution if an attacker tampers with cache files.

grav insecure-deserialization code-execution web-application
2r 2t
critical advisory

Grav Form Plugin Anonymous Page Content Overwrite Vulnerability

Grav Form plugin versions before 9.1.0 allow unauthenticated users to overwrite page content by uploading a malicious markdown file, leading to potential privilege escalation by crafting a new super-admin user.

grav-plugin-form grav cms file-upload privilege-escalation content-overwrite
2r 2t