Server-Side Template Injection in Grav CMS by GetGrav
CVE-2026-72827
8.7HIGH
What is CVE-2026-72827?
Grav CMS versions prior to 2.0.13 are susceptible to a server-side template injection vulnerability. This critical issue arises from unsanitized input in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands. By leveraging the unsandboxed find filter, attackers can inject malicious Twig payloads into the email subject, body, or recipient fields. This flaw can lead to remote code execution when forms are submitted, putting users at significant risk.
Affected Version(s)
grav 0 < 2.0.13
grav 2.0.13
