PT-2026-71996 · Grav Cms · Grav Cms

·

CVE-2026-72827

·

Published

2026-08-14

·

Updated

2026-08-14

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grav CMS versions prior to 2.0.13
Description Low-privileged page editors can execute arbitrary operating-system commands due to a server-side template injection. This occurs when attackers inject Twig payloads—a template engine for PHP—using the unsandboxed find filter within the email-action parameters. The issue is triggered during form submission via the email subject, body, to, or from fields.
Recommendations Update Grav CMS to version 2.0.13 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72827
GHSA-XX48-97M4-H7QM

Affected Products

Grav Cms