High severity8.1NVD Advisory· Published Aug 18, 2026
CVE-2026-75829
CVE-2026-75829
Description
grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.twig enabled. Attackers can submit crafted header and content parameters to execute server-side template injection payloads that are evaluated at render time.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <1.0.15
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.