Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Kuba0123

#16377of 56,333
17.6Total CVSS
Vulnerabilities · 2
High
2
PT-2026-71988
8.8
2026-08-14
Grav Cms · Grav Cms · CVE-2026-72819
**Name of the Vulnerable Software and Affected Versions** Grav CMS versions prior to 2.0.13 **Description** Authenticated users can achieve remote code execution through a flaw in the Flex Objects plugin settings validation. By utilizing array notation instead of string notation, an attacker can bypass routine name validation to call the `unZip()` routine with a malicious ZIP archive. This process allows the upload and writing of PHP files directly to the web root for subsequent execution. **Recommendations** Update Grav CMS to version 2.0.13 or later.
PT-2026-71996
8.8
2026-08-14
Grav Cms · Grav Cms · CVE-2026-72827
**Name of the Vulnerable Software and Affected Versions** Grav CMS versions prior to 2.0.13 **Description** Low-privileged page editors can execute arbitrary operating-system commands due to a server-side template injection. This occurs when attackers inject Twig payloads—a template engine for PHP—using the unsandboxed `find` filter within the email-action parameters. The issue is triggered during form submission via the email subject, body, to, or from fields. **Recommendations** Update Grav CMS to version 2.0.13 or later.