These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The Grav Data Manager plugin versions 1.0.1 through 1.4.4 are vulnerable to stored XSS via the item-detail view. An unauthenticated visitor can store an HTML payload that executes as JavaScript in the session and origin of an administrator who later opens that entry in the classic admin panel. This occurs because the plugin renders stored data entries without proper escaping, using Twig's `raw` filter, an [truncated]
CVE-2026-100672 debrief: Unauthenticated comment data exposure in Grav CMS Comments plugin allows attackers to access sensitive information. Affected product: Grav CMS with Comments plugin up to version 1.2.10. Vulnerability class: Unauthenticated remote data exposure. Likely operational impact: Potential unauthorized access to sensitive comment data, risk of email address exposure for commenters, and pos [truncated]
CVE-2026-92917 debrief: Authenticated users with page-edit rights can exploit a flaw in Grav's Twig content sandbox to dump the entire merged configuration, exposing sensitive information such as SMTP credentials and API tokens. This vulnerability allows attackers to access configuration values that may include SMTP credentials, API tokens, and cache backend passwords. The issue arises from the Twig conte [truncated]
CVE-2026-92916 debrief based on the supplied source corpus. Grav is a flat-file CMS with a high-severity vulnerability allowing unauthenticated access to sensitive information when the debugger is enabled. The Clockwork profiler endpoint exposes session cookies, passwords, and system configuration. Defenders should prioritize verifying exposure and applying patches or workarounds to prevent potential unau [truncated]
The Grav API plugin (getgrav/grav-plugin-api) before version 1.0.18 does not apply the API-key scope cap in the injectSecurityTab() function of BlueprintController. This allows a caller holding a scoped API key to potentially see and edit page permission fields beyond the scope granted to the key. The issue arises from raw isSuperAdmin()/hasPermission() checks without a request parameter, which cannot enf [truncated]
The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. This critical vulnerability allows an API key scoped below full super authority but belonging to a super-admin account to act against other super-admin accounts, potentially disabling their 2FA, deleting their avata [truncated]
CVE-2026-76846 is a high-severity vulnerability in Grav, a content management system, with a CVSS score of 8.7. The vulnerability occurs due to an incomplete default denylist in the Twig sandbox configuration, allowing attackers with page-edit permission to retrieve sensitive system configuration values using Twig templates when config_access is enabled. This could lead to potential sensitive information [truncated]
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsandboxed Twig templates. An authenticated remote user with only api.access and api.pages.write permissions can place a Twig expression in header.form.process.email.body, publish the page, and submit the form to execute an arbitrary operating-system command as the account running PHP. [truncated]
The CVE-2026-72702 vulnerability is a critical origin validation bypass in Grav CMS before version 2.0.16. This vulnerability, with a CVSS score of 9.3, allows an attacker controlling a domain that begins with the victim site's origin to bypass the Referer-based origin check by manipulating the Referer header. To verify and mitigate this vulnerability, defenders should review the official CVE Program reco [truncated]
The CVE-2026-72701 vulnerability in Grav CMS before 2.0.16 involves a timing issue in the Utils::verifyNonce() function. This function uses non-constant-time string comparison with the === operator for CSRF nonce validation, allowing attackers to measure response timing differences and recover valid nonce values byte-by-byte through multiple requests. This weakness in CSRF protection can be exploited by a [truncated]
CVE-2026-72700 is a high-severity vulnerability in the getgrav/grav-plugin-login Composer plugin, which is used by Grav. The plugin compares password reset and account activation tokens using a non-constant-time string comparison, potentially allowing attackers to recover valid tokens through timing differences. However, the vendor rates the practical exploitability as low, and no end-to-end network explo [truncated]
The Grav Login plugin (getgrav/grav-plugin-login) before version 3.9.1 is vulnerable to email address enumeration. This vulnerability arises from the register() method in classes/Login.php, which throws a distinct exception (EMAIL_NOT_AVAILABLE) when a submitted email address already belongs to an existing account. The lack of rate limiting on the registration endpoint allows an attacker to enumerate whic [truncated]
The CVE-2026-72698 vulnerability in Grav CMS before version 2.0.16 allows content editors with page-content edit access to read sensitive configuration values by bypassing the config_denied_paths restrictions using dot notation in Twig templates. This could lead to exposure of secrets like cache credentials. Site administrators and users with page-content edit access in Grav CMS installations prior to ver [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T02:16:45.407Z and has not been modified since then. The NVD entry is currently Deferred. CVE-2026-72697 is a path traversal vulnerability in Grav CMS before 2.0.16. The media_directory() Twig function fails to validate filesystem paths, allowing authenticated users with page authoring privileges [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T02:16:45.097Z and has not been modified since then. The CVE-2026-72695 record indicates a path traversal vulnerability in Grav before 2.0.16, specifically in MediaUploadTrait::deleteFile(). Authenticated users with media management permissions can delete arbitrary files by supplying filenames wit [truncated]
The Grav Login plugin, versions before 1.0.16, contains a critical vulnerability (CVE-2026-56710) that allows attackers with api.users.write permission to clear login lockout counters on admin.super accounts. This effectively removes brute-force protection from high-privilege accounts. Administrators and users of Grav Login plugin, especially those with high-privilege accounts, should be aware of this vul [truncated]
The vulnerability exists in Grav before 3.9.2, specifically in the sendInvitationEmail() function, which fails to validate untrusted Host headers. This allows attackers to manipulate invitation links and redirect users to attacker-controlled domains, bypassing the require_trusted_host protection that only covers password reset flows. Affected systems may be exposed to Host header injection attacks. The CV [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T02:16:42.783Z and has not been modified since then. The NVD entry is currently Deferred. The Grav API plugin before version 1.0.16 contains a server-side request forgery (SSRF) vulnerability in its webhook delivery mechanism. This vulnerability allows attackers to bypass hostname validation throu [truncated]
The Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode. This allows users with page-edit access to render any registered Flex collection without permission checks, potentially exposing sensitive directory contents including user account information. Administrators and users of affected versions should prioritize patching to pre [truncated]
The Grav API Plugin for Grav CMS provides RESTful API access to site content. Prior to version 1.0.8, a basic panel user could exploit the plugin's authorization mechanism to create a persistent credential bound to another user's account, potentially gaining administrative write access. This issue was fixed in version 1.0.8. The vulnerability allows basic panel users to bypass authorization and create cre [truncated]
CVE-2026-64851 Grav Shortcode Core stored cross-site scripting. The Grav Shortcode Core plugin, used for developing shortcode plugins utilizing common formats like WordPress and BBCode, had a vulnerability prior to version 6.2.2. The plugin passed shortcode syntax through Security::detectXss() without proper encoding. This allowed an attacker to concatenate an attacker-controlled parameter into HTML. An a [truncated]
CVE-2026-64850 Grav Blueprint dynamicData Remote Code Execution. Grav is a file-based Web platform. Prior to 2.0.7, an account with admin.pages or api.pages.write can exploit the dynamicData function in Blueprint.php to execute commands as the web server user. This issue is fixed in version 2.0.7. Administrators and developers should assess exposure and apply the patch. The vulnerability allows for remote [truncated]
CVE-2026-63408 debrief: The Grav API Plugin for Grav CMS has a critical vulnerability (CVE-2026-63408) that exposes JWT tokens through URL logs. This issue, fixed in version 1.0.0-rc.16, allows potential token reuse by parties with access to logs and headers, impacting API privileges. Defenders must assess exposure and secure token handling practices, especially for state-changing endpoints. The vulnerabi [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T16:18:37.863Z and has not been modified since then. The NVD entry is currently 8.2 HIGH. The Grav API plugin prior to 1.0.0-rc.16 returns Access-Control-Allow-Origin: * and permissive OPTIONS responses for authenticated /api/v1 endpoints. This allows JavaScript from any origin to submit an attack [truncated]
CVE-2026-62673 is a HIGH severity vulnerability in Grav, a file-based Web platform. Prior to version 2.0.4, the .htaccess and webserver-configs/htaccess.txt security rules do not use the Apache [NC] flag, leading to case-sensitive comparisons of sensitive directory and file-extension patterns. On case-insensitive filesystems, unauthenticated attackers can bypass security rules using uppercase directory or [truncated]
CVE-2026-62672 Grav denial of service via regex_replace filter allows authenticated page editors to publish a catastrophically backtracking pattern that consumes PHP worker CPU and denies service to site visitors. Site administrators and developers using Grav should assess exposure and update to version 2.0.4 or later. The issue is fixed in Grav version 2.0.4. This vulnerability impacts site performance a [truncated]
The CVE-2026-62671 vulnerability in the Grav Login plugin allows an attacker to overwrite a user's TOTP secret via a GET request, forcing two-factor re-enrollment. This issue is fixed in version 3.8.11. The vulnerability is caused by the login.regenerate2FASecret task accepting a top-level GET request without requiring a login-form nonce, an Origin check, or a Referer check. Under the default SameSite=Lax [truncated]
CVE-2026-62670 is a medium-severity vulnerability in the Grav Flex Objects Plugin. An authenticated user with limited permissions can perform actions on a directory without proper authorization. The issue is fixed in version 1.4.3. Defenders should assess exposure and apply the patch. The vulnerability allows unauthorized directory actions due to a flaw in the requireFlexPermission() method. This method f [truncated]
CVE-2026-62669 is a high-severity vulnerability in the Grav Login plugin, which allows an attacker to bypass two-factor authentication (2FA) and gain unauthorized access to a user's account. The vulnerability exists in versions prior to 3.8.11 and is caused by the login.regenerate2FASecret task only checking if the pending-session user exists, rather than requiring the user to be authorized. An attacker c [truncated]
CVE-2026-62668 Grav API Plugin WebhookController.php and WebhookDispatcher.php vulnerability debrief. The Grav API Plugin for Grav CMS provides full headless access to site content via a RESTful API. Prior to version 1.0.6, the plugin's WebhookController.php accepts webhook URLs with only FILTER_VALIDATE_URL syntax validation. Additionally, WebhookDispatcher.php initializes cURL without CURLOPT_PROTOCOLS [truncated]