Getgrav

Grav-plugin-api

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 05.09.2026 12:09:09
  • Zuletzt bearbeitet 08.09.2026 20:05:53

Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can send password ...

  • EPSS 0.23%
  • Veröffentlicht 05.09.2026 12:09:08
  • Zuletzt bearbeitet 08.09.2026 20:05:53

grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but fails to strip dot-keyed equivalents like api.super. A non-super u...

  • EPSS 0.22%
  • Veröffentlicht 05.09.2026 12:09:07
  • Zuletzt bearbeitet 08.09.2026 20:05:53

grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch password fields on g...

  • EPSS 0.39%
  • Veröffentlicht 26.08.2026 10:28:12
  • Zuletzt bearbeitet 03.09.2026 05:15:14

The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses isSuperAdmin() on the acting account rathe...

  • EPSS 0.3%
  • Veröffentlicht 19.08.2026 16:00:06
  • Zuletzt bearbeitet 09.09.2026 21:13:25

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.8, the Grav API plugin intercepts the apiKeyGenerate and apiKeyRevoke admin tasks in user/plugins/api/api.php and authorizes the cal...

  • EPSS 0.36%
  • Veröffentlicht 19.08.2026 15:53:08
  • Zuletzt bearbeitet 09.09.2026 21:13:25

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0-rc.16, the Grav API plugin JwtAuthenticator::extractBearerToken() accepts a JWT from the token URL query parameter on every /api/...

  • EPSS 0.27%
  • Veröffentlicht 19.08.2026 15:51:36
  • Zuletzt bearbeitet 09.09.2026 21:13:25

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0-rc.16, the Grav API plugin CorsMiddleware returns Access-Control-Allow-Origin: * and permissive OPTIONS responses for authenticate...

  • EPSS 0.29%
  • Veröffentlicht 19.08.2026 15:43:19
  • Zuletzt bearbeitet 09.09.2026 21:13:25

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API plugin ApiKeyManager::generateKey() stores a declared scopes array, but ApiKeyAuthenticator::authenticate() does not...

  • EPSS 0.43%
  • Veröffentlicht 19.08.2026 15:36:37
  • Zuletzt bearbeitet 09.09.2026 21:13:25

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, Grav API plugin UsersController::createApiKey(), generate2fa(), and disable2fa() omit the accessGrantsSuper() target check used b...

  • EPSS 0.33%
  • Veröffentlicht 19.08.2026 15:29:24
  • Zuletzt bearbeitet 09.09.2026 21:13:25

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API plugin WebhookController.php accepts webhook URLs after only FILTER_VALIDATE_URL syntax validation, and WebhookDispa...