[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#Grav

articleHIGH 8.2

Unauthenticated Path Traversal in Grav via Missing Directory-Boundary Check

A critical vulnerability (CVE-2026-74907, CVSS 8.2) exists in Grav, a popular PHP-based content management system. The flaw, caused by a missing directory-boundary check in the `plugin-asset-map.php` static asset server, allows unauthenticated attackers to perform path traversal attacks. This can lead to unauthorized file disclosure, potentially resulting in RCE, data exfiltration, or admin-equivalent control. The vulnerability affects Grav versions 2.0.15 and the devel branch, but only when a specific plugin configuration file (`user/config/plugin-asset-map.php`) is present and in use.

Sep 18, 20261 source
newsHIGH 8.7

Unauthenticated Denial of Service in Grav via Unbounded Image Derivative Dimensions

An unauthenticated visitor can exhaust server memory and CPU by requesting an image with oversized resize dimensions in Grav, potentially taking the host down. This affects any Grav site that serves images with no account, plugin, or non-default config required. The vulnerability has a CVSS score of 8.7.

Aug 15, 20261 source