CVE-2026-72831
- EPSS 0.3%
- Veröffentlicht 14.08.2026 11:35:37
- Zuletzt bearbeitet 31.08.2026 20:52:56
The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiController::update() checks only the general Flex directory permission and does not apply the additiona...
CVE-2026-72829
- EPSS 0.3%
- Veröffentlicht 14.08.2026 11:35:36
- Zuletzt bearbeitet 31.08.2026 20:38:54
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. These methods enforce the scope cap only for api.users.write, but gate super-privilege grants on a ba...
CVE-2026-72827
- EPSS 0.47%
- Veröffentlicht 14.08.2026 11:35:35
- Zuletzt bearbeitet 08.09.2026 20:32:39
Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands. Attackers can inject Twig payloads using the unsandboxed...
CVE-2026-72828
- EPSS 0.27%
- Veröffentlicht 14.08.2026 11:35:35
- Zuletzt bearbeitet 31.08.2026 20:30:14
Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsController. The strip-super and accept-groups decisions are gated on a bare isSuperAdmin() check rather than a scope-aware permission check, so ...
CVE-2026-72826
- EPSS 0.3%
- Veröffentlicht 14.08.2026 11:35:34
- Zuletzt bearbeitet 08.09.2026 20:32:39
The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey. The self-target path of requireApiKeyPermission() requires only the baseline api.access...
CVE-2026-72824
- EPSS 0.47%
- Veröffentlicht 14.08.2026 11:35:33
- Zuletzt bearbeitet 31.08.2026 20:38:54
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-toggle check uses a bare isSuperAdmin() gate that does not consult api_key_scopes, so a least-privilege ...
CVE-2026-72825
- EPSS 0.2%
- Veröffentlicht 14.08.2026 11:35:33
- Zuletzt bearbeitet 08.09.2026 20:32:39
The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /reports/twig-content/allowlist endpoint (ReportsController). The endpoint enforces requirePermission('api.config.write') followed by a bare isSuperAdmi...
CVE-2026-72823
- EPSS 0.19%
- Veröffentlicht 14.08.2026 11:35:32
- Zuletzt bearbeitet 31.08.2026 20:30:14
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope cap bypass in DemoController. Its private requireSuper() method checks isSuperAdmin() and returns early before invoking requirePermission(), so the api_key_scopes c...
CVE-2026-72822
- EPSS 0.35%
- Veröffentlicht 14.08.2026 11:35:31
- Zuletzt bearbeitet 31.08.2026 20:38:54
The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, disable2fa authorizes the admin (non-self) path solely via ACL re...
CVE-2026-72820
- EPSS 0.34%
- Veröffentlicht 14.08.2026 11:35:30
- Zuletzt bearbeitet 08.09.2026 20:32:39
Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive directories outside GRAV_ROOT when not in the hard-coded deny-list. Attackers with profile editor access can configure backup profiles with...