Gridx 1.3 is susceptible to remote code execution via tests/support/stores/test_grid_filter.php, which allows remote attackers to execute arbitrary code via crafted values submitted to the $query parameter.
id: CVE-2020-19625
info:
name: Gridx 1.3 - Remote Code Execution
author: geeknik
severity: cr
...