Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-72831 — Grav through 2.0.11 Authentication Bypass via Flex Objects

The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiController::update() checks only the general Flex di…

grav | Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.8 CRITICAL
CVE-2026-72830 — Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass

Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with a scoped api.con…

grav | Remote | Authentication
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.8 CRITICAL
CVE-2026-72829 — Grav before 1.0.13 API Key Scope Bypass via UsersController

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. These methods enforce the scope cap only for api.u…

grav | Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
8.6 HIGH
CVE-2026-72828 — Grav before 1.0.13 API Key Scope Bypass via InvitationsController

Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsController. The strip-super and accept-groups decisions are gated on a bare isSuperAdmin() ch…

grav | Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
8.8 HIGH
CVE-2026-72827 — Grav CMS before 2.0.13 Remote Code Execution via Twig

Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands. Attac…

grav | Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.8 CRITICAL
CVE-2026-72826 — Grav before 1.0.13 Scope Bypass via createApiKey

The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey. The self-target path of requireApiKe…

grav | Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.6 HIGH
CVE-2026-72825 — Grav before 1.0.13 API-key scope cap bypass via ReportsController

The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /reports/twig-content/allowlist endpoint (ReportsController). The endpoint enforces requirePermission…

grav | Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.8 CRITICAL
CVE-2026-72824 — Grav before 1.0.13 API Key Scope Bypass via PagesController

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-toggle check uses a bare isSuperAdmin() gate that doe…

grav | Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.4 MEDIUM
CVE-2026-72823 — Grav before 1.0.13 API-key scope cap bypass via DemoController

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope cap bypass in DemoController. Its private requireSuper() method checks isSuperAdmin() and returns early before in…

grav | Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.8 CRITICAL
CVE-2026-72822 — Grav before 1.0.13 Authentication Bypass via disable2fa

The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, disable2fa aut…

grav | Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.4 MEDIUM
CVE-2026-72821 — Grav Form Plugin before 9.1.15 Stored XSS via Radio Toggle

Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field option labels rendered with the Twig |raw filter. Attackers with form authoring p…

grav | Remote | Cross-Site Scripting
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.9 MEDIUM
CVE-2026-72820 — Grav 2.0.11 Path Traversal via Backup Profile Configuration

Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive directories outside GRAV_ROOT when not in the hard-coded deny-list. Attackers with profi…

grav | Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
8.8 HIGH
CVE-2026-72819 — Grav CMS before 2.0.13 Remote Code Execution via ZIP Upload

Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file …

grav | Remote | Misconfiguration
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.9 MEDIUM
CVE-2026-72817 — go-chi chi 0.9.0 before 5.3.0 IP Spoofing via X-Forwarded-For

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-…

Remote | Misconfiguration
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.9 MEDIUM
CVE-2026-72816 — go-chi chi before 5.3.0 IP Spoofing via RealIP Middleware

go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X…

Remote | Misconfiguration
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.9 MEDIUM
CVE-2026-72815 — go-chi chi v5.2.1 IP Spoofing via X-Forwarded-For Header

go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remo…

Remote | Misconfiguration
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.3 MEDIUM
CVE-2026-72814 — actix-web before 0.6.10 Information Disclosure via Files

The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability. When a non-existing folder is passed as the serve_from argument to Files::new(), the mount pa…

actix-web | Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.9 MEDIUM
CVE-2026-72813 — actix-files before 0.6.10 Denial of Service via empty Range header

actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the pr…

actix-web | Remote | Denial of Service
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.9 MEDIUM
CVE-2026-72812 — SiYuan before v3.7.4 Missing Authorization via refreshBacklink

SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshBacklink endpoint that allows anonymous readers to trigger persistent server-side writes. Attackers …

Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
10.0 CRITICAL
CVE-2026-72811 — SiYuan before v3.7.4 SQL Injection via backlink search

SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor t…

Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
Showing 20 of 10643 Results