What is CVE-2026-75829?
CVE-2026-75829 is due to grav-plugin-api before version 1.0.15 failing to validate Twig content in the translate() endpoint, enabling attackers with api.pages.write permission to perform server-side template injection when process.twig is enabled. Updating to the latest version is recommended.
Azərbaycanca: CVE-2026-75829 zəifliyi grav-plugin-api plagini 1.0.15-dən əvvəlki versiyalarda translate() endpoint-indəki Twig məzmununun düzgün yoxlanılmaması səbəbindən yaranır. Bu, api.pages.write icazəsi olan hücumçulara process.twig aktiv olduqda şablon inyeksiyası həyata keçirməyə imkan verir. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
In which component was CVE-2026-75829 discovered?
This vulnerability was discovered in the grav-plugin-api plugin, in versions prior to 1.0.15.
What permission must an attacker have to successfully exploit CVE-2026-75829?
The attacker must have the api.pages.write permission.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.