Skip to content
Critical Vulnerabilities in Grav and Gravity Forms Plugins Exploited

Critical Vulnerabilities in Grav and Gravity Forms Plugins Exploited

First seen 18 Sep 2026, 20:23 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 21:24 UTC
  • CVE-2026-75827 in Grav allows remote code execution via arbitrary file writes.
  • CVE-2026-87796 in Gravity Forms enables unauthenticated file uploads, risking remote code execution.
  • Both vulnerabilities have PoCs available, increasing the urgency for patching.

Two significant vulnerabilities have been disclosed affecting Grav and the Multi Uploader for Gravity Forms plugin. Grav versions up to 2.0.13 are vulnerable to an arbitrary file write issue (CVE-2026-75827), allowing attackers with specific access to execute remote code. The Multi Uploader for Gravity Forms plugin, up to version 1.1.9, suffers from an arbitrary file upload vulnerability (CVE-2026-87796), enabling unauthenticated attackers to upload malicious files. Both vulnerabilities have been assigned high to critical CVSS scores, with CVE-2026-87796 rated at 9.8. Proof-of-concept (PoC) exploits are available for both vulnerabilities, raising concerns about their potential exploitation in the wild. Security professionals are advised to update affected systems immediately to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-18
CVE-2026-75827 published
Grav disclosed an arbitrary file write vulnerability affecting versions up to 2.0.13.
Sploitus
2026-08-19
CVE-2026-64850 published
Another vulnerability affecting Grav was published, adding to security concerns.
Date unknown
2026-09-17
CVE-2026-87796 published
Multi Uploader for Gravity Forms disclosed an arbitrary file upload vulnerability affecting versions up to 1.1.9.
Sploitus
2026-09-18
First public PoC for CVE-2026-87796
Proof-of-concept code for the Gravity Forms vulnerability was made public, increasing exploitation risk.
Sploitus

More articles in this cluster (2)

Following this threat?

Track CVE-2026-64850 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed