Product
high
advisory
CVE-2026-72700: Timing Vulnerability in Grav Login Plugin
1 TTP 1 CVEThe Grav login plugin for Composer is vulnerable to token-recovery via timing attacks due to non-constant-time string comparisons and a lack of rate limiting on password reset endpoints.
grav-plugin-login
credential-access
vulnerability
web-application
1t
1c
critical
advisory
Grav Login Plugin Privilege Escalation Vulnerability
2 rules 1 TTP 1 IOCUnauthenticated users can escalate privileges to admin in Grav CMS by manipulating registration data due to missing server-side validation in the Login plugin.
Login Plugin +2
grav
privilege-escalation
web
2r
1t
1i