Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code. Attackers can bypass routine name validation by using array notation instead of string notation, call the unZip routine with a malicious archive, and write PHP files to the web root for execution. | |
| Title | Grav CMS before 2.0.13 Remote Code Execution via ZIP Upload | |
| First Time appeared |
Getgrav
Getgrav grav |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Getgrav
Getgrav grav |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-14T14:44:04.272Z
Reserved: 2026-08-10T15:12:16.754Z
Link: CVE-2026-72819
Updated: 2026-08-14T14:42:35.673Z
Status : Received
Published: 2026-08-14T12:16:44.873
Modified: 2026-08-14T15:17:10.317
Link: CVE-2026-72819
No data.
OpenCVE Enrichment
Updated: 2026-08-14T13:30:05Z