Server-Side Template Injection Vulnerability in Grav Plugin API by Grav
CVE-2026-75829

8.6HIGH

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-75829?

The Grav Plugin API is susceptible to a server-side template injection vulnerability due to inadequate validation of Twig content in the translate() endpoint. Attackers possessing api.pages.write permissions can exploit this flaw by submitting malicious header and content parameters, which enables the execution of crafted Twig payloads at render time. This could lead to unauthorized modifications and potentially harmful operations on affected websites.

Affected Version(s)

grav 0 < 1.0.15

grav 1.0.15

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

arpitjain099
.