CVE-2020-29553: Getgrav Grav CMS

High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.

The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF).

Affected products

  • Getgrav Grav CMS: up to and including 1.6.31; version 1.7.0 only

Published 2021-03-15. Last modified 2026-06-17.