Path Traversal Vulnerability in Grav Plugin API by Getgrav
CVE-2026-75830

7.1HIGH

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-75830?

The Grav Plugin API prior to version 1.0.15 contains a path traversal vulnerability within the batchCopy() method of the PagesController. This issue arises because an incomplete fix for a previous vulnerability failed to validate the user-controlled 'suffix' parameter, allowing authenticated users with editor-level permissions to inject path traversal sequences. This could enable them to manipulate filesystem locations accessible by the web server, thus allowing unauthorized writing of content and media files.

Affected Version(s)

grav 0 < 1.0.15

grav 1.0.15

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ivanesk315
.