VYPR
Critical severity9.8NVD Advisory· Published Jan 16, 2026· Updated Jun 17, 2026

CVE-2021-47812

CVE-2021-47812

Description

GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code through the scheduler endpoint. Attackers can exploit the admin-nonce parameter to inject base64-encoded payloads and create malicious custom jobs with system command execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Getgrav/Gravinferred2 versions
    =1.10.7+ 1 more
    • (no CPE)range: =1.10.7
    • cpe:2.3:a:getgrav:grav:1.10.7:*:*:*:*:*:*:*
  • Grav CMS/GravCMSllm-fuzzy
    Range: <1.10.7

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.