Getgrav
Getgrav Grav-plugin-api: vulnerabilidades y CVE
Getgrav Grav-plugin-api tiene 27 vulnerabilidades publicadas, 27 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE27
Últimos 12 meses27
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-86195 | Alta (8.7) | 0.39% | — | 5 sept 2026 | grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but fails to strip dot-keyed… |
| CVE-2026-86193 | Alta (8.7) | 0.36% | — | 5 sept 2026 | grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write… |
| CVE-2026-80204 | Crítica (9.3) | 0.24% | — | 26 ago 2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18 does not apply the API-key scope cap in the injectSecurityTab() function of BlueprintController when deciding whether a page's security/permissions blueprint… |
| CVE-2026-80203 | Crítica (9.3) | 0.51% | — | 26 ago 2026 | The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses… |
| CVE-2026-75833 | Alta (8.6) | 0.22% | — | 18 ago 2026 | The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before version 1.0.14 contains an open redirect weakness in SsoController::sanitizeReturnTo(). The function rejects a literal… |
| CVE-2026-75832 | Crítica (9.3) | 0.30% | — | 18 ago 2026 | The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a missing authorization vulnerability in BlueprintPathResolver::resolveUserScope(). The method gates… |
| CVE-2026-75829 | Alta (8.6) | 0.41% | — | 18 ago 2026 | grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.twig enabled. Attackers can submit… |
| CVE-2026-72829 | Alta (8.7) | 0.47% | — | 14 ago 2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. These methods enforce the scope cap only for api.users.write, but gate… |
| CVE-2026-72828 | Alta (8.6) | 0.49% | — | 14 ago 2026 | Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsController. The strip-super and accept-groups decisions are gated on a bare isSuperAdmin() check rather than a… |
| CVE-2026-72826 | Alta (8.7) | 0.47% | — | 14 ago 2026 | The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey. The self-target path of requireApiKeyPermission()… |
| CVE-2026-72825 | Alta (7.2) | 0.35% | — | 14 ago 2026 | The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /reports/twig-content/allowlist endpoint (ReportsController). The endpoint enforces requirePermission('api.config.write')… |
| CVE-2026-72824 | Alta (8.7) | 0.73% | — | 14 ago 2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-toggle check uses a bare isSuperAdmin() gate that does not consult… |
| CVE-2026-72823 | Media (5.3) | 0.33% | — | 14 ago 2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope cap bypass in DemoController. Its private requireSuper() method checks isSuperAdmin() and returns early before invoking… |
| CVE-2026-72822 | Alta (8.7) | 0.56% | — | 14 ago 2026 | The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, disable2fa authorizes the admin… |
| CVE-2026-72833 | Alta (8.7) | 0.47% | — | 14 ago 2026 | The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulnerability. A scoped API key minted on a super-admin account bypasses its declared scope cap on four… |
| CVE-2026-65896 | Alta (7.1) | 0.48% | — | 23 jul 2026 | Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POST /pages/{route}/move endpoint. PagesController::move() sanitizes the slug only with… |
| CVE-2026-65007 | Alta (8.7) | 0.37% | — | 21 jul 2026 | The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks before the account-management ACL runs… |
| CVE-2026-62387 | Alta (7.1) | 0.34% | — | 17 jul 2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default CORS configuration on all responses, including authenticated endpoints and preflight (OPTIONS)… |
| CVE-2026-62386 | Alta (8.2) | 0.43% | — | 17 jul 2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query parameter on every API route (JwtAuthenticator::extractBearerToken fallback). Because tokens are… |
| CVE-2026-62233 | Alta (8.7) | 0.44% | — | 17 jul 2026 | grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, allowing non-super api.users.write managers to escalate to super-admin. Attackers can mint API… |
| CVE-2026-62231 | Alta (8.6) | 0.39% | — | 17 jul 2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can be created with a restricted scopes array, but the ApiKeyAuthenticator class never reads or enforces these… |
| CVE-2026-61457 | Media (5.3) | 0.83% | — | 15 jul 2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media controller. HandlesMediaUploads::validateFileExtension() inspects only the final file extension via… |
| CVE-2026-61452 | Media (6.9) | 0.33% | — | 15 jul 2026 | The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where JWT access tokens are issued without a jti (JWT ID) claim and therefore cannot be revoked… |
| CVE-2026-61451 | Crítica (9.4) | 0.42% | — | 15 jul 2026 | The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoint. The sanitizeHttpUrl() function only checks… |
| CVE-2026-61456 | Media (5.1) | 0.24% | — | 10 jul 2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the POST /api/v1/media endpoint. The HandlesMediaUploads::processUploadedFile() method validates only the file… |
| CVE-2026-58654 | Media (5.3) | 0.44% | — | 8 jul 2026 | The Grav API plugin (getgrav/grav-plugin-api) 1.0.0 contains an unrestricted file upload vulnerability in the avatar upload endpoint (/api/v1/users/user/avatar). The endpoint validates only the client-declared MIME type… |
| CVE-2026-42843 | Alta (8.8) | 0.49% | — | 11 may 2026 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configuration, users, and system management. Prior to 1.0.0-beta.15, an insecure direct object reference… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.