Getgrav

Grav-plugin-api

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 14.08.2026 11:35:33
  • Zuletzt bearbeitet 14.08.2026 18:19:08

The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /reports/twig-content/allowlist endpoint (ReportsController). The endpoint enforces requirePermission('api.config.write') followed by a bare isSuperAdmi...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 11.05.2026 17:16:34
  • Zuletzt bearbeitet 27.05.2026 19:07:10

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configuration, users, and system management. Prior to 1.0.0-beta.15, an insecure direct object reference and logic flaw in the Grav API pl...