Known Vulnerabilities for Grav-plugin-api by Grav
Listed below are 10 of the newest known vulnerabilities associated with "Grav-plugin-api" by "Grav".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65897 json | Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authent... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65896 json | Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POS... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65895 json | Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowi... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65603 json | The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-65008 json | Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Commo... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-65007 json | The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin ... | Not Provided | 2026-07-21 | 2026-07-23 |
| CVE-2026-62387 json | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default CORS c... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-62386 json | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query para... | Not Provided | 2026-07-17 | 2026-07-23 |
| CVE-2026-62236 json | grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASecret f... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-62233 json | grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, all... | Not Provided | 2026-07-17 | 2026-07-17 |