Getgrav

Grav-plugin-api

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 19.08.2026 15:18:15
  • Zuletzt bearbeitet 09.09.2026 21:13:25

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.2, the Grav API plugin POST /api/v1/media pipeline in HandlesMediaUploads::processUploadedFile() validates an SVG filename extension...

  • EPSS 0.28%
  • Veröffentlicht 18.08.2026 11:19:42
  • Zuletzt bearbeitet 08.09.2026 20:32:39

grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability in the PagesController::batchCopy() method. An incomplete fix for GHSA-qjq4-jp55-4mx2 left the user-controlled 'suffix' parameter...

  • EPSS 0.26%
  • Veröffentlicht 14.08.2026 11:35:39
  • Zuletzt bearbeitet 30.09.2026 18:18:38

The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulnerability. A scoped API key minted on a super-admin account bypasses its declared scope cap on four isSuperAdmin()-gated write endpoints ...

  • EPSS 0.27%
  • Veröffentlicht 14.08.2026 11:35:35
  • Zuletzt bearbeitet 31.08.2026 20:30:14

Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsController. The strip-super and accept-groups decisions are gated on a bare isSuperAdmin() check rather than a scope-aware permission check, so ...

  • EPSS 0.3%
  • Veröffentlicht 14.08.2026 11:35:34
  • Zuletzt bearbeitet 08.09.2026 20:32:39

The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey. The self-target path of requireApiKeyPermission() requires only the baseline api.access...

  • EPSS 0.2%
  • Veröffentlicht 14.08.2026 11:35:33
  • Zuletzt bearbeitet 08.09.2026 20:32:39

The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /reports/twig-content/allowlist endpoint (ReportsController). The endpoint enforces requirePermission('api.config.write') followed by a bare isSuperAdmi...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 11.05.2026 17:16:34
  • Zuletzt bearbeitet 27.05.2026 19:07:10

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configuration, users, and system management. Prior to 1.0.0-beta.15, an insecure direct object reference and logic flaw in the Grav API pl...