CVE-2026-56700
Analyzed
9.8
Grav
Grav
Grav CMS is vulnerable to remote code execution via insecure PHP object deserialization, OS command injection, and server-side template injection.
2 high and critical vulnerabilities covered by CVE Brief since 2026-03-31, each with independent analyst commentary.
← All vendors RSS feed Watch this vendor2 CVEs in the last 12 months
1 products in total
Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.
Grav CMS is vulnerable to remote code execution via insecure PHP object deserialization, OS command injection, and server-side template injection.
Grav CMS v1