Skip to content
Grav 2.1 is out: every page speaks Markdown. Read the announcement →

Shinyhunter hack using Grav CMS vulnerability

Started by DrPen 2 days ago · 2 replies · 79 views
9 hours ago

We've addressed quite a few file upload attacks this year, but without details about the version of Grav it's hard to know exactly what this is, if it's 100% valid etc. Best advise is to always stay up to date with Grav updates, as we handle submitted security advisories in a timely fashion and release often to ensure we're putting the most secure versions of Grav out there for people to update to.

8 hours ago

Hi Andy, thanks for response. However, this is not about me. I shared this because every major cyber news type website is featuring this news - so it's maybe a big problem for the reputation of Grav as a secure CMS. Perhaps your great team might consider a public statement, and release your response to this particular attack, to assure the wider dev community, if you haven't done that already.

Check out just how widely this is being shared, for example: https://search.brave.com/search?q=shinyhunters+Grav+CMS

Suggested topics

Topic Participants Replies Views Activity
Site Feedback · by Sergi, 1 week ago
1 133 1 week ago
Site Feedback · by pamtbaau, 1 month ago
3 335 1 month ago
Site Feedback · by pamtbaau, 2 months ago
3 445 2 months ago
Site Feedback · by pamtbaau, 2 months ago
3 320 2 months ago
Site Feedback · by Karmalakas, 2 months ago
3 433 2 months ago