SHOW LES: ## CVE-2026-72819, CVSS 8.8 (HIGH) - Grav CMS
https://nvd.nist.gov/vuln/detail/CVE-2026-72819
Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code.
“Technology is best when it brings people together.” – Matt Mullenweg




Comments
Oof
Authenticated users? Doesn't seem like that big of a deal...
I am glad i stuck with mkdocs so all my site gets converted to static files before being deployed to my server