CVE-2026-61607 | GetGrav Grav API Plugin up to 1.0.1 Media Upload /api/v1/media processUploadedFile unrestricted upload

SecurityVulns

A vulnerability was found in GetGrav Grav API Plugin up to 1.0.1. It has been declared as critical. This impacts the function HandlesMediaUploads::processUploadedFile of the file /api/v1/media of the component Media Upload Handler. Such manipulation leads to unrestricted upload.

This vulnerability is uniquely identified as CVE-2026-61607. The attack can be launched remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More