Feed/GHSA-pp9r-ppc4-25w4
GHSA-pp9r-ppc4-25w4HIGHCVSS 8.8

Duplicate Advisory: Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation

Published Jul 23, 2026·Updated Sep 17, 2026

NVD Description

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-c4wf-2xxc-68qm. This link is maintained to preserve external references. ### Original Description Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() resolves blueprint data-*@: directives by calling call_user_func_array() on attacker-influenced input, validating only that the target is callable (is_callable()) without restricting dangerous functions such as exec, system, passthru, or shell_exec. Because FlexDirectory registers this handler for every Flex directory, it bypasses the validation added to Blueprint::dynamicData() in 2.0.7 (GHSA-fj2p-qj2f-74v5). Any authenticated user with create or update permission on any Flex-based directory (Flex Users, Flex Pages, Flex Objects, or custom Flex types) can execute arbitrary shell commands on the server.

Affected Packages (1)

getgrav/gravCOMPOSER
From 1.7.0
Fixed in 2.0.9

Public Exploits & PoCs100 found

PoC: wp2shell-PoC

CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept

60

PoC: cve-2026-41940-PoC

A cPanel and WHM authentication bypassing tool

32

PoC: CVE-2026-77991

CVE-2026-77991 - joomlaeventmanager.net - Critical - Privileged POST /administrator/index.php - Remote Code Execution

1

PoC: CVE-2026-93453

CVE-2026-93453 Exploit — SOGo password reset link poisoning via attacker-controlled Origin header, enabling password reset token interception and account takeover.

1

PoC: CVE-2026-23744

exploit para reverse shell en MCPJamInspector v1.4.2< por endpoint mal configurado

1

PoC: rep-openai-artifactory

Forensic Analysis and Local Replication of the OpenAI-Artifactory Privilege Escalation Incident (CVE-2026-65616)

1

PoC: CVE-2026-76461

CVE-2026-76461

1

PoC: CVE-2026-76460

CVE-2026-76460

1

PoC: ghostlock-pfem10

GhostLock (CVE-2026-43499) for OPPO Find X5 Pro (PFEM10) — OPlus watchdog & heap-spray detector reverse engineering

1

PoC: MSRMapper

MSRMapper is a manual kernel driver mapper for Windows x64 that abuses CVE-2025-8061 in the vulnerable Lenovo driver LnvMSRIO.sys to perform a BYOVD (Bring Your Own Vulnerable Driver) attack.

1

PoC: spip-exploits

spip exploits for CVE-2026-72708, CVE-2026-72709, CVE-2026-72710

1

PoC: CVE-2026-65330

My first CVE

1

PoC: ghost-hoock

GhostLock stripped to one primitive: SELinux off on Galaxy A17 (BZA5) via futex PI UAF (CVE-2026-43499). No root, no cred patch, no rwforge.

1

PoC: CVE-2026-13447

CVE-2026-13447 - WordPress - inspireui - Critical 9.8 - Unauthenticated POST /wp-json/api/flutter_user/firebase_sms_v2 - Authentication Bypass

PoC: CVE-2026-19952

CVE-2026-19952 - DynamiApps - High 7.5 - Unauthenticated POST /wp-admin/admin-ajax.php - Arbitrary File Deletion

PoC: CVE-2026-75816

CVE-2026-75816 - Frontend Admin by DynamiApps for Wordpress - Critical 9.8 - Unauthenticated POST /wp-admin/admin-ajax.php - Account Takeover

PoC: CVE-2026-33439-PoC

CVE-2026-33439 OpenAM pre-auth RCE PoC

PoC: hpim-training-lab

Trained to Escalate: Forensic Analysis and Local Replication of RLHF-Induced Privilege Escalation in AI Agents (CVE-2026-65616)

PoC: CVE-2026-78159

CVE-2026-78159 - stellarwp - Critical 9.8 - Unauthenticated POST /wp-comments-post.php - Remote Code Execution

PoC: CVE-2026-74469

CVE-2026-74469

PoC: CVE-2026-68121

CVE-2026-68121

PoC: CVE-2026-81000

CVE-2026-81000

PoC: CVE-2026-80844

CVE-2026-80844

PoC: CVE-2026-18937

CVE-2026-18937 - Broken Link Checker - Critical 9.0 - Unauthenticated GET /?page_id=4&shortcode_tags[blcpoc]=po... - Remote Code Execution

PoC: CVE-2026-93659-writeup

Stored XSS in Concrete CMS Community Store leads to admin dashboard takeover

PoC: cve-2026-75157-poc

Standalone authorized universal HTTP PoC for CVE-2026-75157

PoC: news-8.6.0-cve-2026-8726-backport

Minimal security backport for CVE-2026-8726 in georgringer/news 8.6.0

PoC: PoC_CVE-2024-28157

PoC for (CVE-2024-28157) Stored XSS in Jenkins GitBucket Plugin <= 0.8

PoC: log4shell-audit

Log4Shell (CVE-2021-44228) security review documentation and advisory triage

PoC: CVE-2026-45140

CVE-2026-45140 - chamilo - Critical 9.8 - Unauthenticated POST /plugin/CStudio/editor/import-project... - Remote Code Execution

PoC: CVE-2026-75827

CVE-2026-75827 - getgrav - High 8.8 - Unauthenticated GET /poc-form - Arbitrary File Write

PoC: CVE-2026-82226

CVE-2026-82226 - Tickera - Critical 9.8 - Unauthenticated POST /cart/ - PHP Object Injection

PoC: CVE-2025-32433-LAB

A Flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials in the Erlang/OTP SSH server

PoC: CVE-2026-84753

CVE-2026-84753 - WPFunnels - Critical 9.8 - Unauthenticated POST /?rest_route=/mint-mail/v1/mint-form-... - PHP Object Injection

PoC: CVE-2026-18464

Security advisory and research notes for CVE-2026-18464 affecting the WP Maps Pro WordPress plugin.

PoC: CVE-2026-16265

Security advisory and research notes for CVE-2026-16265 affecting the WP Maps WordPress plugin.

PoC: copyfail

Copy-Fail-Exploit-CVE-2026-31431

PoC: K80Pro-miro-CVE-2026-64560

Device-bound CVE-2026-64560 adaptation for RedMi K80pro miro OS 3.0.304.0

PoC: Grafana-Plugin-Enumerator-CVE-2021-43798

Enumerate Grafana plugin enumeration PoC for CVE-2021-43798

PoC: MS09-050

MS09-050 (CVE-2009-3103) SMBv2 srv2.sys buffer overflow exploit with built-in scanner, arch auto-detection, and standalone reverse shell payloads for x86/x64. No Metasploit required.

PoC: CVE-2026-18574

CVE-2026-18574 - Draft or TODO

PoC: CVE-2026-91843

CVE-2026-91843 - Draft or TODO

PoC: CVE-2026-77179

CVE-2026-77179 - Draft or TODO

PoC: CVE-2026-87796

CVE-2026-87796 - Multi Uploader for Gravity Forms <= 1.1.9; Unauthorized RCE (CRITICAL 9.8)

PoC: zenfone9-root

Temporary root (uid 0) on a bootloader-locked ASUS Zenfone 9 via CVE-2025-21479 + a perf-based physical-address leak. GPLv3.

PoC: CVE-2026-32604

A PoC exploit for CVE-2026-32604 - Spinnaker GitRepo Artifact RCE

PoC: CVE-2026-1961-foreman-poc

PoC for CVE-2026-1961 — command injection in Foreman's WebSocket proxy (lib/ws_proxy.rb) via unsanitized compute resource hostname, leading to RCE as the foreman user. Responsibly disclosed and patched.

PoC: CVE-2026-87930

CVE-2026-87930 Joomla Multi-CVE RCE suite — authorized testing only

PoC: CVE-2026-27540

CVE-2026-27540 WWLC WordPress unauth upload RCE suite — authorized testing only

PoC: CVE-2026-85706-PoC-Toolkit

🪬 CVE-2026-85706 – GitLab Unauth File Read Toolkit (CVSS 10.0) | Red/Blue Team suite for self-managed GitLab CE/EE 18.7–19.3.1. 2 tools: Full Exploit (unauth file read, admin token, mass scan, loot, shell, stealth, SQLite/HTML/JSON output) etc., SafeChecker (version detect, audit, security headers, TLS check, MITRE). Only Use Ethically, Educ. <3

PoC: CVE-2026-88533

PoC and lab reproduction for CVE-2026-88533

PoC: CVE-2026-48908

CVE-2026-48908 SP Page Builder (Joomla) unauth RCE suite — authorized testing only

PoC: CVE-2026-92805

UVdesk unauth wizard super-admin POC

PoC: CVE-2026-49179-Active-Directory-WriteSPNScript-Command-Injection

CVE-2026-49179: Active Directory WriteSPNScript Command Injection

PoC: CVE-2026-85706

CVE-2026-85706

PoC: bigint-buffer-js

Pure-JS drop-in for bigint-buffer@1.1.5 without the vulnerable native binding (CVE-2025-3194)

PoC: CVE-2026-19975

CVE-2026-19975 - Draft or TODO

PoC: CVE-2026-67401

PoC for CVE-2026-67401 — cPanel/WHM EmailTrack SQL injection leading to arbitrary file write and root RCE. Includes a self-contained vulnerable lab, SQLi detection, and full exploit chain.

PoC: cve-2026-59827-metabase-cyber-range

Educational cyber range for CVE-2026-59827 (Metabase H2 unsafe deserialization / CWE-502). Isolated Docker lab — training only, not for attacking production Metabase.

PoC: cve-2025-57819-freepbx-range

Isolated educational FreePBX-compatible cyber range for CVE-2025-57819 (CWE-89/CWE-288). Docker lab — not official Sangoma FreePBX.

PoC: CVE-2026-12793

CVE-2026-12793 - JetFormBuilder Unauthorized RCE (CRITICAL 9.8)

PoC: CVE-2026-55781-poc

Unbounded memory allocation in NanaZip's UFS handler via an attacker-controlled `fs_bsize` field.

PoC: CVE-2025-32432-exploit-by-P34NUT

A exploit to obtain RCE in CRAFTCMS

PoC: CVE-2026-84600

Information on the security content of Apple software updates

PoC: CVE-2026-12944

Langflow 1.10.0 urllib SSRF

PoC: agentic-workflow-injection

Reproducible vulnerable/fixed fixtures for agentic workflow injection in GitHub Actions (CVE-2026-44246), plus measured detector coverage

PoC: Container_escape

container escape POCs for CVE-2026-80521 and CVE-2026-52910

PoC: CVE-2026-89026

Issabel pbxapi hard coded JWT RCE POC

PoC: doris-spark-connector-cve

Unofficial Apache Doris Spark connector 26.1.0 security fork for Java / Spark 3.5.1 / Scala 2.12; patched shaded Jackson for CVE-2026-54512.

PoC: asus-i005-cve-2026-43499

CVE-2026-43499 (GhostLock) adaptation for ASUS ROG Phone 5S — UAF trigger + pselect stack reclaim, KASLR leak blocked

PoC: CVE-2026-56096

Proof of Concept and Write-up for CVE-2026-56096 (Blind Parameter Injection in TYPO3 EXT:solr)

PoC: CVE-2022-22715

Blogpost: https://whereisk0shl.top/post/break-me-out-of-sandbox-in-old-pipe-cve-2022-22715-windows-dirty-pipe

PoC: CVE-2026-12793

CVE-2026-12793 PoC — JetFormBuilder ≤3.6.2 unauth Register User / admin account creation

PoC: upb-any-recursion-audit

Ruby/PHP upb Any-recursion audit: falsified vs CVE-2026-0994 bug class

PoC: Public_Exploit-1--Wordpress-CVE-2021-29447

CVE-2021-29447 is an authenticated XML External Entity (XXE) vulnerability in WordPress

PoC: CVE-2026-22686-RemoteCodeExecution-RCE-PoC

CVE-2026-22686-RemoteCodeExecution-RCE-PoC

PoC: ios.CVE-2026-84616-84607

research on finding the bug and fix of CVE-2026-84616 and CVE-2026-84607

PoC: POC-CVE-2026-49975

Security research PoC for CVE-2026-49975: HTTP/2 HPACK compression bomb + flow-control hold DoS in Apache mod_http2

PoC: zte-blade-v40-vita-unlock

Unlocking the ZTE Blade V40 Vita (P606F02 / Unisoc UMS9230 / UFS) bootloader via CVE-2022-38694 - Linux scripts, the FBE post-unlock hang fix, and the two traps nobody documents

PoC: CVE-2026-5430

CVE-2026-5430 - Draft or TODO

PoC: heartbleed-lab

CVE-2014-0160 (Heartbleed) lab: vulnerable OpenSSL 1.0.1f in Docker, a memory-leak PoC, and a demo. Authorised lab use only.

PoC: CVE-2026-65374

CVE-2026-65374 - Draft or TODO

PoC: CVE-2024-27815

CVE-2024-27815 - XNU kernel heap buffer overflow in sbconcat_mbufs()

PoC: CVE-2026-82329-PoC-Exploit

🧰 CVE-2026-82329 – JFrog Artifactory Auth Bypass Toolkit (CVSS 9.8) | Red/Blue Team suite for self-hosted Artifactory 7.x (111-161). 2 tools: Full Exploit (JWTforge, admin token, user create, mass scan, stealth, interactive menu, resistence, WAF bypass etc.), SafeChecker (version detect, audit, JSON report). 🦾 Use Ethically, Stay Legal :V

PoC: CVE-2026-32996

A vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

PoC: CVE-2026-12944

Langflow 1.10.0 urllib SSRF POC

PoC: IonStack_S21

Exploit chain research targeting CVE-2026-43499 on Samsung Galaxy S21

PoC: langflow-CVE-2026-17633-PoC

PoC for CVE-2026-17633 — Authenticated RCE in IBM Langflow OSS 1.0.0–1.10.3 via custom_component endpoint. Includes CVE-2026-17632 AST scanner bypass research.

PoC: CVE-2009-2265-fix

fix for not working exploit script on exploitdb (50057.py)

PoC: CVE-2025-8191

Testing for CVE-2025-8191

PoC: pentest-i021-poc-1789486727

temporary CVE-2024-4367 verification artifacts

PoC: CVE-2026-38526-KrayinCRM

Authenticated Arbitrary File Upload leading to Remote Code Execution Technical analysis and controlled reproduction of CVE-2026-38526 in Webkul Krayin CRM 2.2.x.

PoC: CVE-2026-15315

CVE-2026-15315, CVE-2026-15316 - Draft or TODO

PoC: CVE-2026-65343-e7eb2ed

CVE-2026-65343: OOB read in AppleKeyStore.kext (_LibSer_SEPControl_Deserialize) copies an ACM buffer to userspace without length validation, letting sandboxed processes leak kernel pointers (0xfffffff0…) and defeat KASLR via DYLD_INTERPOSE ACM handle capture. Fixed in iOS 26.6.1 (23G83).

PoC: pedit-cow

exploit for CVE-2026-46331

PoC: CVE-2026-79551-Tenda

Tenda Technology Co., Ltd NVR_4H: CH3 v2.1.V27.5.58.6 was discovered to contain a hardcoded cryptographic key.

PoC: CVE-2026-59346-POC

PoC for CVE-2026-59346 - 32-bit integer overflow in VMware's VMXNET3 TSO segmentation path, guest-to-host crash.

PoC: CVE-2025-5548-FreeFloat-FTP-Lab

Laboratorio académico de análisis y explotación de CVE-2025-5548 en FreeFloat FTP Server 1.0.

PoC: CVE-2026-76461

CVE-2026-76461

PoC: CVE-2022-41404-DoS-Protection

Windows Apache Tomcat resource limits implementation guide for CVE-2022-41404 DoS vulnerability protection

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free