Exploitation of Grav CMS SSTI Vulnerabilities

Exploitation of Grav CMS SSTI Vulnerabilities

First seen 8 Sep 2026, 15:46 UTC Sploitus 54.9

Article Content

Browse articles
ThreatCluster

Recent exploits targeting Grav CMS have emerged, leveraging the SSTI vulnerability (CVE-2024-28116). Two proof-of-concept scripts, GenGravSSTIExploit and Graver, allow attackers to inject remote code execution (RCE) payloads on vulnerable systems. These scripts require valid user credentials for authentication, indicating that the attacks are more targeted. The exploits can create malicious pages on affected servers, enabling attackers to execute arbitrary commands. Grav CMS versions affected include those prior to the patch for CVE-2024-28116. The tools are available on GitHub, raising concerns about potential misuse. Security professionals are advised to monitor their systems and apply necessary patches. The situation is evolving, with potential for increased exploitation as awareness grows.

Key Points: • Grav CMS is vulnerable to SSTI and RCE exploits (CVE-2024-28116). • Two PoC scripts, GenGravSSTIExploit and Graver, are publicly available. • Exploitation requires valid user credentials, indicating targeted attacks.

Ask AI about this cluster

Timeline

2024-03-21
CVE-2024-28116 published
CVE-2024-28116 was published, detailing a critical SSTI vulnerability in Grav CMS.
Sploitus
2024-03-24
First public PoC released
The first proof-of-concept code for exploiting CVE-2024-28116 was made public.
Sploitus
2026-09-07
GenGravSSTIExploit released
A new Python script, GenGravSSTIExploit, was released, enabling RCE on Grav CMS.
Sploitus
2026-09-08
Graver exploit detailed
Another exploit script, Graver, was detailed, highlighting the SSTI vulnerability in Grav CMS.
Sploitus