HIGHVulnerability

CVE-2026-75829

grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.twig enabled. Attackers can submit crafted header and content parameters to execute server-side template injection payloads that are evaluated at render time.

Properties

severity
HIGH
score
8.1
epss_score
0.00289
cve_id
CVE-2026-75829
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
published_at
2026-08-18T12:19:32.827
last_modified
2026-09-08T20:32:39.347
epss_percentile
0.21125

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements Used in a Template Engine

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-75829 — Ninja Signal Threat Intelligence | Ninja Signal