The Grav CMS grav-plugin-database component received security fixes for a SQL injection flaw in PDO::tableExists(), where a table name was interpolated directly into a raw SQL query without sanitization or quoting. The issue, tracked as CVE-2026-58492 and GHSA-8jxg-4pw9-xcwf, could let attacker-controlled input supplied through plugin or developer code execute arbitrary SQL against the configured database, with potential confidentiality and integrity impact. The vulnerability affects versions prior to 1.2.0, and the CVE record notes proof-of-concept exploitation status with non-automatable exploitation and partial technical impact.
A related code update in the Grav Database plugin replaced the unsafe table lookup with a parameterized, driver-aware catalog query and also addressed a second hardening issue, GHSA-jm58-p4pv-qcwc, involving DSN attribute injection. The patch validates connection-setting fields, casts ports to integers, and removes PostgreSQL credentials from the DSN, while also adding an onDatabaseDrivers event to support third-party database drivers.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-10, CVE-2026-58492 was created for a SQL injection vulnerability in grav-plugin-database's `PDO::tableExists()` method. The record states the flaw affects versions prior to 1.2.0 and notes it was later updated the same day with SSVC metadata including proof-of-concept exploitation status.
On 2026-06-18, getgrav released grav-plugin-database version 1.1.3 with security fixes. The update remediated a potential SQL injection in `tableExists()` by replacing raw table-name interpolation with a parameterized, driver-aware catalog lookup, and also included DSN hardening changes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.