Grav Cms · Grav Cms · CVE-2026-72827
**Name of the Vulnerable Software and Affected Versions**
Grav CMS versions prior to 2.0.13
**Description**
Low-privileged page editors can execute arbitrary operating-system commands due to a server-side template injection. This occurs when attackers inject Twig payloads—a template engine for PHP—using the unsandboxed `find` filter within the email-action parameters. The issue is triggered during form submission via the email subject, body, to, or from fields.
**Recommendations**
Update Grav CMS to version 2.0.13 or later.