Skip to content

Grav Vulnerable to Remote Code Execution (RCE) via Malicious Plugin ZIP Upload in Direct Install Feature

Critical severity GitHub Reviewed Published Apr 27, 2026 in getgrav/grav • Updated May 13, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts