VYPR

Flex Objects

by Grav CMS

CVEs (2)

  • CVE-2026-62235Jul 17, 2026
    risk 0.00cvss epss 0.00

    Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that allows authenticated users with only api.access permission to perform unauthorized CRUD operations on permission-less directories. Attackers with api.access…

  • CVE-2026-58655Jul 15, 2026
    risk 0.00cvss epss 0.01

    The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template injection vulnerability. When rendering dynamic collection or object titles, the plugin passes user-controlled frontmatter values…