
🚨 Grav CMS + API Plugin Mass Disclosure — 11 CVEs, FIVE CVSS 9.8 CVE-2026-72829 (9.8): UsersController → super-admin escalation Update Grav to 2.0.13+ and API Plugin to 1.0.13+ NOW. → https://threataft.com/articles/grav-cms-api-plugin-mass-disclosure-11-cves #cybersecurity #infosec #GravCMS #CMS #API #Security #ThreatIntel
Post summary
Grav CMS hosts 11 critical CVEs, including CVE‑2026‑72829 which allows super‑admin escalation; users are advised to upgrade Grav to 2.0.13+ and API Plugin to 1.0.13+ to apply the patch.
