Server-Side Template Injection Vulnerability in Grav Plugin API by Grav
CVE-2026-75829
8.6HIGH
What is CVE-2026-75829?
The Grav Plugin API is susceptible to a server-side template injection vulnerability due to inadequate validation of Twig content in the translate() endpoint. Attackers possessing api.pages.write permissions can exploit this flaw by submitting malicious header and content parameters, which enables the execution of crafted Twig payloads at render time. This could lead to unauthorized modifications and potentially harmful operations on affected websites.
Affected Version(s)
grav 0 < 1.0.15
grav 1.0.15
