Product
Authorization Bypass in grav-plugin-api
1 TTP 1 CVEThe grav-plugin-api plugin for Grav CMS (before version 1.0.18) contains an authorization flaw in UsersController.php that allows API keys with restricted scopes to perform sensitive administrative actions against super-admin accounts.
Privilege Escalation via Improper API Scope Validation in Grav Plugin
1 TTP 1 CVEThe grav-plugin-api plugin for Grav fails to validate API key scope hierarchy, allowing low-privileged users to mint unrestricted administrative keys via the createApiKey endpoint.
Authentication Scope Bypass in Grav API Plugin Leading to RCE
1 rule 3 TTPs 1 CVEAn API key scope-cap bypass in the Grav API plugin allows attackers with restricted keys to execute server-side templates via Server-Side Template Injection.
Grav API Plugin Authorization Bypass Leads to Account Takeover (CVE-2026-65007)
3 TTPs 1 CVEThe Grav api plugin (grav-plugin-api) versions prior to 1.0.8 contain an authorization bypass vulnerability where the plugin intercepts API key generation and revocation tasks before proper ACL checks, allowing any user with the baseline admin.login permission to generate or revoke API keys for any account, enabling impersonation, privilege escalation, and potential account takeover.
Grav Plugin API Privilege Escalation via Authorization Bypass (CVE-2026-62233)
1 TTP 1 CVEA privilege escalation vulnerability (CVE-2026-62233) in grav-plugin-api before version 1.0.6 allows non-super api.users.write managers to bypass authorization checks on administrative API endpoints, enabling the creation of super-admin API keys or disabling super-admin Two-Factor Authentication (2FA), leading to full Grav instance takeover.