CVE-2020-29553: Getgrav Grav CMS
High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.
The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF).
Affected products
- Getgrav Grav CMS: up to and including 1.6.31; version 1.7.0 only
Published 2021-03-15. Last modified 2026-06-17.