PT-2026-81146 · Grav · Email Plugin

·

CVE-2026-75574

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grav Email plugin versions prior to 4.2.2
Description An authenticated remote user with api.access and api.pages.write permissions can execute arbitrary operating-system commands as the account running PHP. This occurs because the plugin renders Email action parameters controlled by the page editor as unsandboxed Twig templates. An attacker can achieve this by placing a Twig expression in the header.form.process.email.body parameter, publishing the page, and submitting the form. Twig is a template engine used to generate HTML or other text formats dynamically.
Recommendations Update Grav Email plugin to version 4.2.2 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75574

Affected Products

Email Plugin