VulnSea

grav-plugin-api vulnerabilities

CVEs whose affected-version data names the grav-plugin-api package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

3 CVEsRSS

CVE-2026-86196High· 8.7PoC
2w ago

Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains

Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can s…

Midnightgetgrav · grav-plugin-apiEPSS 0.26%via NVD
CVE-2026-86195High· 8.7PoC
2w ago

grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but fails to strip dot-keyed equivalents like api.super

grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but fails to strip dot-keyed equivalents like api.super. …

Midnightgetgrav · grav-plugin-apiEPSS 0.23%via NVD
CVE-2026-86193High· 8.7PoC
2w ago

grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts

grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch passwor…

Midnightgetgrav · grav-plugin-apiEPSS 0.21%via NVD
grav-plugin-api vulnerabilities (CVEs) · VulnSea