Tag
high
advisory
Authentication Scope Bypass in Grav API Plugin Leading to RCE
1 rule 3 TTPs 1 CVEAn API key scope-cap bypass in the Grav API plugin allows attackers with restricted keys to execute server-side templates via Server-Side Template Injection.
grav-plugin-api +2
web-vulnerability
rce
ssti
grav-cms
web-application-vulnerability
cve-2026-75829
1r
3t
1c
updated
high
advisory
Grav API Plugin Missing Authorization Allows Security Settings Modification
1 TTP 1 CVEGrav API Plugin versions prior to 1.0.10 contain a missing authorization vulnerability (CVE-2026-65895) allowing authenticated users with the 'api.config.write' privilege to modify critical security settings, including disabling site-wide rate limiting to enable credential brute-forcing attacks and reconfiguring CORS policies to include attacker-controlled origins with credentials enabled, potentially leading to unauthorized data access.
Grav API Plugin
grav-cms
api-plugin
vulnerability
access-control
cwe-862
1t
1c