Grav CMS RCE Alert: Hackers Love Direct Install, You Won’t!
Grav CMS 1.7.48 is vulnerable to authenticated remote code execution. Thanks to the “Direct Install” feature, adventurous admins can transform their website into a high-tech puppet show, with PHP scripts pulling the strings. Just make sure your malicious plugin has a catchy name—evilplugin has a nice ring to it!

Hot Take:
Grav CMS may have just dug its own grave with this RCE vulnerability. Who knew “Direct Install” could translate to “Directly Install Your Worst Nightmare”? I guess it’s time to grav-itate towards some serious patching!
Key Points:
- Grav CMS version 1.7.48 with Admin Plugin 1.10.48 has an RCE vulnerability.
- Authenticated admins can execute arbitrary PHP code via the “Direct Install” feature.
- This issue is tracked as CVE-2025-50286.
- The vulnerability arises from insufficient validation during plugin uploads.
- Exploitation can lead to full system compromise.
Already a member? Log in here