Sploitus Critical Vulnerabilities in Grav and Gravity Forms Plugins Exploited
Article Content
- •CVE-2026-75827 in Grav allows remote code execution via arbitrary file writes.
- •CVE-2026-87796 in Gravity Forms enables unauthenticated file uploads, risking remote code execution.
- •Both vulnerabilities have PoCs available, increasing the urgency for patching.
Two significant vulnerabilities have been disclosed affecting Grav and the Multi Uploader for Gravity Forms plugin. Grav versions up to 2.0.13 are vulnerable to an arbitrary file write issue (CVE-2026-75827), allowing attackers with specific access to execute remote code. The Multi Uploader for Gravity Forms plugin, up to version 1.1.9, suffers from an arbitrary file upload vulnerability (CVE-2026-87796), enabling unauthenticated attackers to upload malicious files. Both vulnerabilities have been assigned high to critical CVSS scores, with CVE-2026-87796 rated at 9.8. Proof-of-concept (PoC) exploits are available for both vulnerabilities, raising concerns about their potential exploitation in the wild. Security professionals are advised to update affected systems immediately to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-64850 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…