---
id: CVE-2026-75829
title: >-
  grav-plugin-api versions before 1.0.15 fail to validate Twig content in the
  translate() endpoint, allowing attackers with api.pages.write permission to
  persist pages with process.twig enabled
summary: >-
  grav-plugin-api versions before 1.0.15 fail to validate Twig content in the
  translate() endpoint, allowing attackers with api.pages.write permission to
  persist pages with process.twig enabled. Attackers can submit crafted header
  and cont…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-1336
published: '2026-08-18'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:32:39.347'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75829'
references:
  - url: 'https://github.com/getgrav/grav/security/advisories/GHSA-w94c-jmg4-w4c9'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/grav-plugin-api-before-twig-ssti-via-translate-endpoint
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00289
epssPercentile: 0.21706
ingestedAt: '2026-09-08T21:11:12.279Z'
---

## Overview

grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.twig enabled. Attackers can submit crafted header and content parameters to execute server-side template injection payloads that are evaluated at render time.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
