getgrav grav-plugin-api

3 known vulnerabilities in getgrav grav-plugin-api, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-86196 CVSS 8.7 high Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing…
  • CVE-2026-86195 CVSS 8.7 high grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the…
  • CVE-2026-86193 CVSS 8.7 high grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user…