CVE-2026-65008
- EPSS 0.84%
- Veröffentlicht 21.07.2026 11:39:57
- Zuletzt bearbeitet 08.10.2026 16:17:28
Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to call_user_func_array() with...
CVE-2026-65007
- EPSS 0.27%
- Veröffentlicht 21.07.2026 11:39:56
- Zuletzt bearbeitet 23.07.2026 15:17:46
The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks before the account-management ACL runs and authorizes the caller on on...
CVE-2026-64628
- EPSS 0.15%
- Veröffentlicht 21.07.2026 11:39:55
- Zuletzt bearbeitet 23.07.2026 19:17:03
Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS detection scan only matches payloads containing literal angle brackets, allowing shortcode parameters to bypass validation. Attackers with ad...
CVE-2026-62387
- EPSS 0.26%
- Veröffentlicht 17.07.2026 00:07:14
- Zuletzt bearbeitet 17.07.2026 15:44:29
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default CORS configuration on all responses, including authenticated endpoints and preflight (OPTIONS) responses. Because the plugin accept...
CVE-2026-62386
- EPSS 0.27%
- Veröffentlicht 17.07.2026 00:07:13
- Zuletzt bearbeitet 23.07.2026 20:17:19
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query parameter on every API route (JwtAuthenticator::extractBearerToken fallback). Because tokens are embedded in URLs, they are logge...
CVE-2026-62236
- EPSS 0.1%
- Veröffentlicht 17.07.2026 00:07:11
- Zuletzt bearbeitet 17.07.2026 15:44:29
grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASecret frontend task, which regenerates and persists a new TOTP secret for the authenticated session user without any anti-CSRF nonce...
CVE-2026-62237
- EPSS 0.25%
- Veröffentlicht 17.07.2026 00:07:11
- Zuletzt bearbeitet 08.10.2026 16:17:27
Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and function, which are allowlisted in the Twig content sandbox. When Twig processing in page content is enabled (security.twig_conten...
CVE-2026-62235
- EPSS 0.17%
- Veröffentlicht 17.07.2026 00:07:10
- Zuletzt bearbeitet 17.07.2026 15:44:29
Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that allows authenticated users with only api.access permission to perform unauthorized CRUD operations on permission-less directories. A...
CVE-2026-62233
- EPSS 0.25%
- Veröffentlicht 17.07.2026 00:07:09
- Zuletzt bearbeitet 17.07.2026 19:17:18
grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, allowing non-super api.users.write managers to escalate to super-admin. Attackers can mint API keys bound to super-admin account...
CVE-2026-62234
- EPSS 0.3%
- Veröffentlicht 17.07.2026 00:07:09
- Zuletzt bearbeitet 23.07.2026 20:17:19
Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create webhooks with file://, dict://, or gopher:// URLs. Attackers can trigger webhook events to read local fi...