VYPR

scheduler-webhook plugin

by Grav CMS

CVEs (1)

  • CVE-2026-57852Jul 20, 2026
    risk 0.00cvss epss 0.00

    Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured scheduled jobs by exploiting a short-circuit logic flaw in the webhook token validation. Attackers can send a single…