github getgrav/grav 1.7.53.4

3 hours ago

Bugfix

  • [security] A form's upload area could be pointed at a folder outside its temporary storage by tampering with the hidden form id, letting an unauthenticated visitor drop a file elsewhere under the site. The id is now rejected unless it matches the expected characters. Backport of the Grav 2.0 fix (GHSA-hmcx-ch82-3fv2, CVE-2026-42608)

Don't miss a new grav release

NewReleases is sending notifications on new releases.