high
advisory
Unauthenticated Information Disclosure in Grav CMS Clockwork Profiler
Grav CMS versions 1.7.0-1.7.53.2 and 2.0.0-2.0.21 suffer from an unauthenticated information disclosure vulnerability in the Clockwork profiler endpoint when the debugger is enabled.
CVE search metadata
CVE search record: CVE-2026-92916. Severity: high. CVSS: 7.5. KEV: no. Brief: Unauthenticated Information Disclosure in Grav CMS Clockwork Profiler. Brief link: https://feed.craftedsignal.io/briefs/2026-09-grav-cms-info-disclosure/
Grav CMS versions 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21 contain a critical information disclosure vulnerability within the Clockwork profiler endpoint (CVE-2026-92916). When the