CVE-2026-61457 | getgrav Grav up to 1.0.2 API Media Controller validateFileExtension filename unrestricted upload (EUVD-2026-44651)
A vulnerability identified as problematic has been detected in getgrav Grav up to 1.0.2. Impacted is the function validateFileExtension of the component API Media Controller. The manipulation of the argument filename leads to unrestricted upload.
This vulnerability is documented as CVE-2026-61457. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More