CVE-2026-72827 | GetGrav up to 2.0.12 Email Action subject/body/to/from special elements used in a template engine

SecurityVulns

A vulnerability has been found in GetGrav Grav up to 2.0.12 and classified as critical. This issue affects some unknown processing of the component Email Action. The manipulation of the argument subject/body/to/from leads to improper neutralization of special elements used in a template engine.

This vulnerability is uniquely identified as CVE-2026-72827. The attack is possible to be carried out remotely. No exploit exists.

The affected component should be upgraded.VulDB Recent EntriesRead More