CVE-2026-59193Medium· 4.9▾ SunlitGrav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool because Installer::unZip calls ZipArchive::…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
0.4% → 0.6%
Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool because Installer::unZip calls ZipArchive::extractTo without limits on uncompressed size, entry count, or directory depth. This issue is fixed in version 2.0.0.
grav >= 1.0.0, < 2.0.0grav = 2.0.0Upgrade past the affected range:
grav 2.0.0Affected packages:
getgrav/grav >= 1.0.0, < 2.0.0Patched in:
getgrav/grav 2.0.0Connected by shared product, vendor, weakness, or advisory.
GHSA-v626-428r-43p8High· 6.5Duplicate Advisory: Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer
CVE-2026-62672Medium· 6.0Grav is a file-based Web platform
CVE-2026-61690Medium· 6.5Grav is a file-based Web platform
CVE-2026-92916High· 7.5Grav is a flat-file CMS
CVE-2026-92917High· 7.5Grav is a flat-file CMS
CVE-2025-64059Low· 1.8Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor