Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2835▲ 33 respecto a la semana anterior
Críticas / altas1495▲ 276 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 451 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.38% | — | Getgrav Grav API PluginAI | 19/8/2026 | 9/9/2026 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0-rc.16, the Grav API plugin CorsMiddleware returns Access-Control-Allow-Origin: * and permissive OPTIONS responses for authenticated /api/v1 endpoints. JavaScript from any origin can submit an… | |
| Aplazada | Crítica (9.4) | 0.45% | — | Getgrav Grav API PluginAI | 19/8/2026 | 9/9/2026 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API plugin WebhookController.php accepts webhook URLs after only FILTER_VALIDATE_URL syntax validation, and WebhookDispatcher.php initializes cURL without CURLOPT_PROTOCOLS or… | |
| Aplazada | Alta (8.8) | 0.64% | — | Getgrav Grav API PluginAI | 19/8/2026 | 9/9/2026 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, Grav API plugin UsersController::createApiKey(), generate2fa(), and disable2fa() omit the accessGrantsSuper() target check used by sibling user mutation endpoints. A non-super account with… | |
| Aplazada | Alta (8.7) | 0.74% | — | Getgrav Grav API PluginAI | 14/8/2026 | 31/8/2026 | Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. The scope cap is applied only inside requirePermission(), while the scheduler and backups gates use a bare isSuperAdmin() check that never consults… | |
| Aplazada | Alta (8.7) | 0.52% | — | Getgrav Grav API PluginAI | 23/7/2026 | 28/8/2026 | Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invited accounts to groups that grant api.super permissions. Attackers can create invitation records with elevated group membership, and when accepted,… |