CVE-2026-75829

grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.twig enabled. Attackers can submit crafted header and content parameters to execute server-side template injection payloads that are evaluated at render time.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-18 12:19

Updated : 2026-09-08 20:32


NVD link : CVE-2026-75829

Mitre link : CVE-2026-75829

CVE.ORG link : CVE-2026-75829


JSON object : View

Products Affected

No product.

CWE
CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine