These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-62666: Grav API Plugin prior to 1.0.6 has a vulnerability allowing non-super accounts to create API keys with super-admin privileges due to missing access checks in UsersController::createApiKey(), generate2fa(), and disable2fa(). This issue permits rotating or disabling the target's two-factor authentication and obtain the target's full privileges because key scopes are not enforced. The vulnera [truncated]
CVE-2026-61842 debrief: Grav Twig content sandbox vulnerability exposes configuration secrets. The vulnerability allows page authors to render sandboxed content that exposes plugins.* configuration secrets, including SMTP credentials and API keys. Defenders should verify configuration secrets have not been exposed and update to version 2.0.2 or later to fix the issue. The issue is fixed in version 2.0.2. [truncated]
The CVE-2026-61690 vulnerability exists in Grav's ZipArchiver::extract() function, which does not enforce system.gpm.archive uncompressed-size, file-count, or nesting-depth limits. This allows an attacker to cause denial of service by providing a malicious archive. The issue is fixed in version 2.0.1. Users of Grav versions prior to 2.0.1 should update to mitigate this vulnerability. System administrators [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T16:18:16.723Z and has not been modified since then. The NVD entry is currently MEDIUM. This medium-severity vulnerability in the Grav API Plugin for Grav CMS allows an attacker with api.media.write permission to store malicious SVG files that can execute JavaScript when opened by a victim, leadin [truncated]
CVE-2026-53654 is a medium-severity vulnerability in the Grav Login plugin, allowing unauthenticated phishing redirects due to insecure handling of the _redirect field. The issue is fixed in version 3.8.5. Defenders should assess exposure and apply the patch. The vulnerability enables attackers to redirect users to malicious sites, potentially leading to credential theft. Additional monitoring for phishin [truncated]
CVE-2026-75837 Grav Privilege Escalation via Group Access Field. A delegated admin.users operator can escalate to super-admin by manipulating the access field in the core group blueprint, gaining scheduler and Twig evaluation capabilities. This critical vulnerability affects Grav installations, particularly those with delegated admin.users operators. Administrators and users should assess exposure and upd [truncated]
The Grav API plugin before version 1.0.14 has a vulnerability where it fails to enforce the authorize requirement in MenubarController::executeAction(). This allows any authenticated caller with api.access to invoke a privileged menubar action directly, bypassing the intended authorization. The impact is latent on a stock install but affects any first- or third-party plugin relying on the documented autho [truncated]
The CVE-2026-75835 vulnerability in the Grav API plugin allows an authenticated attacker with a scoped API key to bypass scope restrictions and access sensitive metadata and item definitions due to a missing authorization check. This issue, with a CVSS score of 9.3, was publicly disclosed on August 18, 2026, and last modified on September 8, 2026. The vulnerability exists in versions prior to 1.0.14 of th [truncated]
CVE-2026-75834 is a stored cross-site scripting vulnerability in Grav before 2.0.14. An authenticated attacker with page-edit permissions can store malicious JavaScript that executes in the browser of a visitor who views the affected page. This vulnerability exists in the Security::detectXss() function in system/src/Grav/Common/Security.php, where the XSS detection patterns use the PCRE /u (UTF-8) modifie [truncated]
The Grav API plugin, bundled with Grav 2.0's admin-next/API stack, contains an open redirect weakness in SsoController::sanitizeReturnTo(). This function rejects a literal '//' prefix but does not account for browsers normalizing backslashes to slashes in special (http/https) schemes. Consequently, an attacker-supplied returnTo parameter could redirect an authenticated victim to an attacker-controlled sit [truncated]
The Grav API plugin, bundled with Grav 2.0, contains a missing authorization vulnerability in BlueprintPathResolver::resolveUserScope(). An attacker holding an API key scoped only to api.media.write can bypass authorization and write a file into another user's scope, potentially leading to unauthorized privilege escalation and data tampering. This vulnerability affects Grav installations using the Grav AP [truncated]
CVE-2026-75831 is a stored cross-site scripting vulnerability in Grav before 2.0.15. The vulnerability exists in the audio and video media rendering through the sourceParsedownElement method. An attacker can inject arbitrary HTML and JavaScript by concatenating unescaped media URL fragments into rawHtml source elements, which executes in viewers' sessions.
CVE-2026-75830 is a path traversal vulnerability in the grav-plugin-api, specifically in the PagesController::batchCopy() method. An authenticated user with the api.pages.write permission can supply path traversal sequences in the suffix parameter to write attacker-controlled page content and media to arbitrary filesystem locations. This vulnerability allows for potential data tampering and unauthorized c [truncated]
CVE-2026-75829 is a high-severity vulnerability in the grav-plugin-api, which allows attackers with api.pages.write permission to execute server-side template injection payloads via the translate() endpoint. This vulnerability has a CVSS score of 8.6 and was published on 2026-08-18. The vulnerability is caused by the failure of grav-plugin-api versions before 1.0.15 to validate Twig content in the transla [truncated]
CVE-2026-75828 is a stored cross-site scripting vulnerability in Grav before 2.0.15. Authenticated editors can inject event handlers that execute in visitor browsers when page content is rendered. This vulnerability allows attackers to inject malicious scripts, potentially leading to unauthorized actions and data breaches. Defenders should assess exposure and prioritize remediation to prevent exploitation [truncated]
CVE-2026-75827 Grav Arbitrary File Write Vulnerability. The vulnerability exists in Grav before 2.0.15, where an incomplete denylist in Blueprint dynamic-data bare-function validation allows attackers with page-edit or blueprint-config access to invoke the error_log function and append PHP payloads to web-accessible files, achieving remote code execution. Defenders should assess exposure and prioritize pa [truncated]
The Grav Form Plugin before version 9.1.19 is vulnerable to stored cross-site scripting (XSS) attacks. This vulnerability allows attackers with form authoring privileges to inject arbitrary HTML and JavaScript into form templates, which can then be executed by all form visitors. The vulnerability is due to the plugin's failure to properly escape field-definition properties, including prepend, append, spac [truncated]
CVE-2026-74908 Grav plugin-api before 1.0.15 contains a script injection vulnerability where the SVG sanitizer only checks for the exact extension 'svg', allowing .svgz and .xhtml files to bypass sanitization and be stored unsanitized. Attackers with api.media.write permission can upload files containing executable script payloads that execute in the site origin when accessed by administrators or visitors.
CVE-2026-74907 is a high-severity path traversal vulnerability in Grav before 2.0.15. The vulnerability exists in the static asset server within index.php, allowing unauthenticated attackers to access files in sibling directories by exploiting directory names that extend the base path string. This vulnerability can lead to unauthorized file access, potentially resulting in data breaches or further exploit [truncated]
The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulnerability. A scoped API key minted on a super-admin account bypasses its declared scope cap on four isSuperAdmin()-gated write endpoints (in GroupsController, AccountsConfigController, PreferencesController, and DashboardWidgetController). These endpoints authorize via a super-admin early-retur [truncated]
A stored cross-site scripting vulnerability exists in Grav versions from 1.5.2 through 2.0.12 in the Security::detectXss() function. A page editor without admin.super privileges can save malicious page content that is executed when visited by other users. The vulnerability allows an attacker to execute arbitrary JavaScript code in the context of other users, potentially leading to session theft, sensitive [truncated]
The Flex Objects plugin for Grav contains an authorization vulnerability in its Flex Objects API, allowing an authenticated account with limited permissions to change super administrator passwords or grant admin rights, potentially leading to full site takeover. The issue was addressed in Flex Objects 1.4.7. Evidence is limited to public CVE and NVD records. Users should review and verify their installati [truncated]
The Grav API plugin, versions before 1.0.13, contains a vulnerability that allows scoped API keys to write scheduler configuration due to improper enforcement of API key scope caps in ConfigController super-scope gates. This can lead to operating system command execution as the web server user. The vulnerability arises because the scope cap is applied only inside requirePermission(), whereas the scheduler [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-14T12:16:46.157Z and has not been modified since then. The NVD entry is currently Received. This HIGH severity vulnerability (CVSS score of 8.7) affects Grav API plugin versions before 1.0.13, allowing an API-key scope-cap bypass in UsersController's create() and update() methods. These methods enfo [truncated]
CVE-2026-72828 is a HIGH severity vulnerability in Grav Plugin API before 1.0.13. The InvitationsController fails to enforce API-key scope caps, allowing a least-privilege API key to create an invitation record with super-admin access flags, resulting in privilege escalation. Users should verify and apply patches promptly to prevent potential exploitation. This vulnerability has a CVSS score of 8.6 and wa [truncated]
CVE-2026-72827 is a server-side template injection vulnerability in Grav CMS before version 2.0.13. The vulnerability allows low-privileged page editors to execute arbitrary operating-system commands via email-action parameters. Attackers can inject Twig payloads in email fields to achieve remote code execution when forms are submitted. This vulnerability has a high severity score and requires immediate a [truncated]
The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey. This allows an attacker with a minimal-scope API key on a super account to create an unscoped, full-access super key, potentially enabling further exploitation. The vulnerability is rated HIGH with a CVSS score of 8.7, indicating a high severity [truncated]
The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /reports/twig-content/allowlist endpoint. This vulnerability allows an attacker to append attacker-chosen tokens to the security.twig_sandbox allowlist, potentially leading to SSTI/RCE. The endpoint enforces requirePermission('api.config.write') followed by a bare isSuperAdmin() check instead of requireSuper( [truncated]
The Grav API plugin (getgrav/grav-plugin-api) before version 1.0.13 is vulnerable to server-side template injection (SSTI) and remote code execution due to an API key scope-cap bypass in PagesController::guardTwigContent(). This vulnerability allows a least-privilege API key scoped only to api.pages.write to enable process.twig on a page save when security.twig_content.process_enabled=true and editor_enab [truncated]
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope cap bypass in DemoController. This vulnerability allows any scoped API key minted on a super account to bypass its scope restrictions when calling the baseline() and reset() operations, potentially leading to demo-engine control issues. Organizations using the Grav API plugin, especially those with demo mode configured a [truncated]