getgrav grav-plugin-api
3 known vulnerabilities in getgrav grav-plugin-api, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-86196 CVSS 8.7 high Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing…
- CVE-2026-86195 CVSS 8.7 high grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the…
- CVE-2026-86193 CVSS 8.7 high grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user…