PatchSiren

getgrav CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH getgrav CVE published 2026-09-26

CVE-2026-100673

The Grav Data Manager plugin versions 1.0.1 through 1.4.4 are vulnerable to stored XSS via the item-detail view. An unauthenticated visitor can store an HTML payload that executes as JavaScript in the session and origin of an administrator who later opens that entry in the classic admin panel. This occurs because the plugin renders stored data entries without proper escaping, using Twig's `raw` filter, an [truncated]

HIGH getgrav CVE published 2026-09-26

CVE-2026-100672

CVE-2026-100672 debrief: Unauthenticated comment data exposure in Grav CMS Comments plugin allows attackers to access sensitive information. Affected product: Grav CMS with Comments plugin up to version 1.2.10. Vulnerability class: Unauthenticated remote data exposure. Likely operational impact: Potential unauthorized access to sensitive comment data, risk of email address exposure for commenters, and pos [truncated]

HIGH getgrav CVE published 2026-09-17

CVE-2026-92917

CVE-2026-92917 debrief: Authenticated users with page-edit rights can exploit a flaw in Grav's Twig content sandbox to dump the entire merged configuration, exposing sensitive information such as SMTP credentials and API tokens. This vulnerability allows attackers to access configuration values that may include SMTP credentials, API tokens, and cache backend passwords. The issue arises from the Twig conte [truncated]

HIGH getgrav CVE published 2026-09-17

CVE-2026-92916

CVE-2026-92916 debrief based on the supplied source corpus. Grav is a flat-file CMS with a high-severity vulnerability allowing unauthenticated access to sensitive information when the debugger is enabled. The Clockwork profiler endpoint exposes session cookies, passwords, and system configuration. Defenders should prioritize verifying exposure and applying patches or workarounds to prevent potential unau [truncated]

CRITICAL getgrav CVE published 2026-08-26

CVE-2026-80204

The Grav API plugin (getgrav/grav-plugin-api) before version 1.0.18 does not apply the API-key scope cap in the injectSecurityTab() function of BlueprintController. This allows a caller holding a scoped API key to potentially see and edit page permission fields beyond the scope granted to the key. The issue arises from raw isSuperAdmin()/hasPermission() checks without a request parameter, which cannot enf [truncated]

CRITICAL getgrav CVE published 2026-08-26

CVE-2026-80203

The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. This critical vulnerability allows an API key scoped below full super authority but belonging to a super-admin account to act against other super-admin accounts, potentially disabling their 2FA, deleting their avata [truncated]

HIGH getgrav CVE published 2026-08-25

CVE-2026-76846

CVE-2026-76846 is a high-severity vulnerability in Grav, a content management system, with a CVSS score of 8.7. The vulnerability occurs due to an incomplete default denylist in the Twig sandbox configuration, allowing attackers with page-edit permission to retrieve sensitive system configuration values using Twig templates when config_access is enabled. This could lead to potential sensitive information [truncated]

HIGH getgrav CVE published 2026-08-25

CVE-2026-75574

The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsandboxed Twig templates. An authenticated remote user with only api.access and api.pages.write permissions can place a Twig expression in header.form.process.email.body, publish the page, and submit the form to execute an arbitrary operating-system command as the account running PHP. [truncated]

CRITICAL getgrav CVE published 2026-08-25

CVE-2026-72702

The CVE-2026-72702 vulnerability is a critical origin validation bypass in Grav CMS before version 2.0.16. This vulnerability, with a CVSS score of 9.3, allows an attacker controlling a domain that begins with the victim site's origin to bypass the Referer-based origin check by manipulating the Referer header. To verify and mitigate this vulnerability, defenders should review the official CVE Program reco [truncated]

MEDIUM getgrav CVE published 2026-08-25

CVE-2026-72701

The CVE-2026-72701 vulnerability in Grav CMS before 2.0.16 involves a timing issue in the Utils::verifyNonce() function. This function uses non-constant-time string comparison with the === operator for CSRF nonce validation, allowing attackers to measure response timing differences and recover valid nonce values byte-by-byte through multiple requests. This weakness in CSRF protection can be exploited by a [truncated]

HIGH getgrav CVE published 2026-08-25

CVE-2026-72700

CVE-2026-72700 is a high-severity vulnerability in the getgrav/grav-plugin-login Composer plugin, which is used by Grav. The plugin compares password reset and account activation tokens using a non-constant-time string comparison, potentially allowing attackers to recover valid tokens through timing differences. However, the vendor rates the practical exploitability as low, and no end-to-end network explo [truncated]

CRITICAL getgrav CVE published 2026-08-25

CVE-2026-72699

The Grav Login plugin (getgrav/grav-plugin-login) before version 3.9.1 is vulnerable to email address enumeration. This vulnerability arises from the register() method in classes/Login.php, which throws a distinct exception (EMAIL_NOT_AVAILABLE) when a submitted email address already belongs to an existing account. The lack of rate limiting on the registration endpoint allows an attacker to enumerate whic [truncated]

HIGH getgrav CVE published 2026-08-25

CVE-2026-72698

The CVE-2026-72698 vulnerability in Grav CMS before version 2.0.16 allows content editors with page-content edit access to read sensitive configuration values by bypassing the config_denied_paths restrictions using dot notation in Twig templates. This could lead to exposure of secrets like cache credentials. Site administrators and users with page-content edit access in Grav CMS installations prior to ver [truncated]

HIGH getgrav CVE published 2026-08-25

CVE-2026-72697

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T02:16:45.407Z and has not been modified since then. The NVD entry is currently Deferred. CVE-2026-72697 is a path traversal vulnerability in Grav CMS before 2.0.16. The media_directory() Twig function fails to validate filesystem paths, allowing authenticated users with page authoring privileges [truncated]

HIGH getgrav CVE published 2026-08-25

CVE-2026-72695

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T02:16:45.097Z and has not been modified since then. The CVE-2026-72695 record indicates a path traversal vulnerability in Grav before 2.0.16, specifically in MediaUploadTrait::deleteFile(). Authenticated users with media management permissions can delete arbitrary files by supplying filenames wit [truncated]

CRITICAL getgrav CVE published 2026-08-25

CVE-2026-56710

The Grav Login plugin, versions before 1.0.16, contains a critical vulnerability (CVE-2026-56710) that allows attackers with api.users.write permission to clear login lockout counters on admin.super accounts. This effectively removes brute-force protection from high-privilege accounts. Administrators and users of Grav Login plugin, especially those with high-privilege accounts, should be aware of this vul [truncated]

HIGH getgrav CVE published 2026-08-25

CVE-2026-56709

The vulnerability exists in Grav before 3.9.2, specifically in the sendInvitationEmail() function, which fails to validate untrusted Host headers. This allows attackers to manipulate invitation links and redirect users to attacker-controlled domains, bypassing the require_trusted_host protection that only covers password reset flows. Affected systems may be exposed to Host header injection attacks. The CV [truncated]

MEDIUM getgrav CVE published 2026-08-25

CVE-2026-56708

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T02:16:42.783Z and has not been modified since then. The NVD entry is currently Deferred. The Grav API plugin before version 1.0.16 contains a server-side request forgery (SSRF) vulnerability in its webhook delivery mechanism. This vulnerability allows attackers to bypass hostname validation throu [truncated]

HIGH getgrav CVE published 2026-08-25

CVE-2026-56707

The Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode. This allows users with page-edit access to render any registered Flex collection without permission checks, potentially exposing sensitive directory contents including user account information. Administrators and users of affected versions should prioritize patching to pre [truncated]

HIGH getgrav CVE published 2026-08-19

CVE-2026-64852

The Grav API Plugin for Grav CMS provides RESTful API access to site content. Prior to version 1.0.8, a basic panel user could exploit the plugin's authorization mechanism to create a persistent credential bound to another user's account, potentially gaining administrative write access. This issue was fixed in version 1.0.8. The vulnerability allows basic panel users to bypass authorization and create cre [truncated]

HIGH getgrav CVE published 2026-08-19

CVE-2026-64851

CVE-2026-64851 Grav Shortcode Core stored cross-site scripting. The Grav Shortcode Core plugin, used for developing shortcode plugins utilizing common formats like WordPress and BBCode, had a vulnerability prior to version 6.2.2. The plugin passed shortcode syntax through Security::detectXss() without proper encoding. This allowed an attacker to concatenate an attacker-controlled parameter into HTML. An a [truncated]

HIGH getgrav CVE published 2026-08-19

CVE-2026-64850

CVE-2026-64850 Grav Blueprint dynamicData Remote Code Execution. Grav is a file-based Web platform. Prior to 2.0.7, an account with admin.pages or api.pages.write can exploit the dynamicData function in Blueprint.php to execute commands as the web server user. This issue is fixed in version 2.0.7. Administrators and developers should assess exposure and apply the patch. The vulnerability allows for remote [truncated]

HIGH getgrav CVE published 2026-08-19

CVE-2026-63408

CVE-2026-63408 debrief: The Grav API Plugin for Grav CMS has a critical vulnerability (CVE-2026-63408) that exposes JWT tokens through URL logs. This issue, fixed in version 1.0.0-rc.16, allows potential token reuse by parties with access to logs and headers, impacting API privileges. Defenders must assess exposure and secure token handling practices, especially for state-changing endpoints. The vulnerabi [truncated]

HIGH getgrav CVE published 2026-08-19

CVE-2026-63407

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T16:18:37.863Z and has not been modified since then. The NVD entry is currently 8.2 HIGH. The Grav API plugin prior to 1.0.0-rc.16 returns Access-Control-Allow-Origin: * and permissive OPTIONS responses for authenticated /api/v1 endpoints. This allows JavaScript from any origin to submit an attack [truncated]

HIGH getgrav CVE published 2026-08-19

CVE-2026-62673

CVE-2026-62673 is a HIGH severity vulnerability in Grav, a file-based Web platform. Prior to version 2.0.4, the .htaccess and webserver-configs/htaccess.txt security rules do not use the Apache [NC] flag, leading to case-sensitive comparisons of sensitive directory and file-extension patterns. On case-insensitive filesystems, unauthenticated attackers can bypass security rules using uppercase directory or [truncated]

MEDIUM getgrav CVE published 2026-08-19

CVE-2026-62672

CVE-2026-62672 Grav denial of service via regex_replace filter allows authenticated page editors to publish a catastrophically backtracking pattern that consumes PHP worker CPU and denies service to site visitors. Site administrators and developers using Grav should assess exposure and update to version 2.0.4 or later. The issue is fixed in Grav version 2.0.4. This vulnerability impacts site performance a [truncated]

MEDIUM getgrav CVE published 2026-08-19

CVE-2026-62671

The CVE-2026-62671 vulnerability in the Grav Login plugin allows an attacker to overwrite a user's TOTP secret via a GET request, forcing two-factor re-enrollment. This issue is fixed in version 3.8.11. The vulnerability is caused by the login.regenerate2FASecret task accepting a top-level GET request without requiring a login-form nonce, an Origin check, or a Referer check. Under the default SameSite=Lax [truncated]

MEDIUM getgrav CVE published 2026-08-19

CVE-2026-62670

CVE-2026-62670 is a medium-severity vulnerability in the Grav Flex Objects Plugin. An authenticated user with limited permissions can perform actions on a directory without proper authorization. The issue is fixed in version 1.4.3. Defenders should assess exposure and apply the patch. The vulnerability allows unauthorized directory actions due to a flaw in the requireFlexPermission() method. This method f [truncated]

HIGH getgrav CVE published 2026-08-19

CVE-2026-62669

CVE-2026-62669 is a high-severity vulnerability in the Grav Login plugin, which allows an attacker to bypass two-factor authentication (2FA) and gain unauthorized access to a user's account. The vulnerability exists in versions prior to 3.8.11 and is caused by the login.regenerate2FASecret task only checking if the pending-session user exists, rather than requiring the user to be authorized. An attacker c [truncated]

CRITICAL getgrav CVE published 2026-08-19

CVE-2026-62668

CVE-2026-62668 Grav API Plugin WebhookController.php and WebhookDispatcher.php vulnerability debrief. The Grav API Plugin for Grav CMS provides full headless access to site content via a RESTful API. Prior to version 1.0.6, the plugin's WebhookController.php accepts webhook URLs with only FILTER_VALIDATE_URL syntax validation. Additionally, WebhookDispatcher.php initializes cURL without CURLOPT_PROTOCOLS [truncated]