CVE-2026-56710
- EPSS 0.28%
- Veröffentlicht 25.08.2026 01:30:11
- Zuletzt bearbeitet 31.08.2026 20:50:15
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on admin.super accounts, removin...
CVE-2026-72695
- EPSS 0.57%
- Veröffentlicht 25.08.2026 01:30:11
- Zuletzt bearbeitet 08.10.2026 16:17:33
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows authenticated users with media management permissions to delete arbitrary files by supplying filenames with directory traversal sequences. The me...
CVE-2026-56709
- EPSS 0.26%
- Veröffentlicht 25.08.2026 01:30:10
- Zuletzt bearbeitet 31.08.2026 20:38:54
Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and redirect users to attacker-cont...
CVE-2026-56708
- EPSS 0.17%
- Veröffentlicht 25.08.2026 01:30:08
- Zuletzt bearbeitet 31.08.2026 20:50:15
Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delivery that allows attackers to bypass hostname validation by DNS rebinding. Attackers controlling authoritative DNS for a configured webhook hostname can...
CVE-2026-56707
- EPSS 0.22%
- Veröffentlicht 25.08.2026 01:30:06
- Zuletzt bearbeitet 31.08.2026 20:52:56
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode that allows users with page-edit access to render any registered Flex collection without permission checks. Attackers ca...
CVE-2026-64850
- EPSS 0.34%
- Veröffentlicht 19.08.2026 15:58:02
- Zuletzt bearbeitet 09.09.2026 21:13:25
Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in system/src/Grav/Common/Data/Blueprint.php sends an editor-controlled Class::method provider and arguments to call_user_func_array() without rejecting dangerous callba...
CVE-2026-62673
- EPSS 0.4%
- Veröffentlicht 19.08.2026 15:46:59
- Zuletzt bearbeitet 09.09.2026 21:13:25
Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess.txt security rules omit the Apache [NC] flag and therefore compare sensitive directory and file-extension patterns case-sensitively. On a case-insens...
- EPSS 0.3%
- Veröffentlicht 19.08.2026 15:44:36
- Zuletzt bearbeitet 09.09.2026 21:13:25
Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the regex_replace filter and function in system/config/security.yaml, and GravExtension::regexReplace() passes an editor-controlled pattern directly to preg_replace(). When security.t...
CVE-2026-62669
- EPSS 0.39%
- Veröffentlicht 19.08.2026 15:40:03
- Zuletzt bearbeitet 09.09.2026 21:13:25
Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.regenerate2FASecret task checks only that the pending-session user exists rather than requiring $user->authorized. After submitti...
CVE-2026-62668
- EPSS 0.33%
- Veröffentlicht 19.08.2026 15:29:24
- Zuletzt bearbeitet 09.09.2026 21:13:25
Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API plugin WebhookController.php accepts webhook URLs after only FILTER_VALIDATE_URL syntax validation, and WebhookDispa...