CVE Tools

Grav-plugin-api

12 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Grav-plugin-api, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Grav-plugin-api CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Grav-plugin-api CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-051
2026-061
2026-070
2026-087
2026-093

Severity

How the 12 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High583%
  • Medium117%

Latest CVEs

The 12 most recently published vulnerabilities affecting Grav-plugin-api.

  1. CVE-2026-86196Grav API Plugin before 1.0.20 Authentication Bypass via Host Header—
  2. CVE-2026-86195grav-plugin-api 1.0.0 through 1.0.19 Privilege Escalation via Dot-Keyed Super Flag—
  3. CVE-2026-86193Grav API Plugin Authentication Bypass via Group-Inherited Super—
  4. CVE-2026-64852Grav API Plugin: Missing authorization on API-key generate/revoke lets any admin.login user forge keys for any account—
  5. CVE-2026-63408Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parameter7.5
  6. CVE-2026-63407Grav API Plugin: CORS 'Access-Control-Allow-Origin: *' on Authenticated API Responses8.2
  7. CVE-2026-62667Grav API Plugin : API Key 'scopes' Never Enforced - Delegated Least-Privilege Keys Carry Full User ACL8.1
  8. CVE-2026-62666Grav API Plugin: non-super api.users.write manager -> super-admin via createApiKey (incomplete fix of CVE-2026-59190); + 2FA strip of super8.8
  9. CVE-2026-62668Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols—
  10. CVE-2026-61607Grav API Plugin: Stored XSS via SVG Upload - API Media Pipeline Bypasses Sanitizer4.6
  11. CVE-2026-11982Stored XSS via missing XSS safety check in Admin2 Pages API partial validation—
  12. CVE-2026-42843grav-plugin-api: Grav API Privilege Escalation to Super Admin8.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store