CVE-2026-58492 UNKNOWN

CVE-2026-58492

Published: 2026-07-10

Description

grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its table argument directly into a raw SQL query string without sanitization, escaping, quoting, or whitelisting, allowing attacker-controlled table names passed by consuming plugin or developer code to execute arbitrary SQL against the configured database. This issue is fixed in version 1.2.0.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…