CVE-2026-72819: Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects
HIGHHigh-risk vulnerability — CVSS 8.8
Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code. Attackers can bypass routine name validation by using array notation instead of string notation, call the unZip routine with a malicious archive, and write PHP files to the web root for execution.
CVE · detail
- CVE-2026-72819nvd ↗EPSS 0.50%
Early access
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.
bot-protected