Path Traversal Vulnerability in Grav Plugin API by Getgrav
CVE-2026-75830
7.1HIGH
What is CVE-2026-75830?
The Grav Plugin API prior to version 1.0.15 contains a path traversal vulnerability within the batchCopy() method of the PagesController. This issue arises because an incomplete fix for a previous vulnerability failed to validate the user-controlled 'suffix' parameter, allowing authenticated users with editor-level permissions to inject path traversal sequences. This could enable them to manipulate filesystem locations accessible by the web server, thus allowing unauthorized writing of content and media files.
Affected Version(s)
grav 0 < 1.0.15
grav 1.0.15
