Skip to content
archivevulnerability · 14 Aug 2026 · 12:16 UTC

CVE-2026-72819: Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects

VULNCVE-2026-72819source · GTH
HIGHHigh-risk vulnerability — CVSS 8.8

last 60 dispatches · spectrum

Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code. Attackers can bypass routine name validation by using array notation instead of string notation, call the unZip routine with a malicious archive, and write PHP files to the web root for execution.

CVE · detail
grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected