Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44043
Total
3569
Critical
13212
High
13018
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-75574 | HIGH | 8.8 | The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsandboxed Twig templates. An authenticated remote user with only api.access and api.pages.write … | Aug 25, 2026 |
| CVE-2026-72702 | MEDIUM | 5.4 | Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, which validate the Referer header using an unanchored string prefix … | Aug 25, 2026 |
| CVE-2026-72701 | LOW | 3.7 | Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string comparison with the === operator instead of hash_equals() for CSRF nonce … | Aug 25, 2026 |
| CVE-2026-72700 | HIGH | 7.5 | The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset and account activation tokens using a non-constant-time === string comparison instead of hash_equals() … | Aug 25, 2026 |
| CVE-2026-72699 | MEDIUM | 5.3 | The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register() method in classes/Login.php throws a distinct exception (EMAIL_NOT_AVAILABLE) when a … | Aug 25, 2026 |
| CVE-2026-72698 | MEDIUM | 6.5 | Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing content editors to read sensitive configuration values. … | Aug 25, 2026 |
| CVE-2026-72697 | MEDIUM | 6.5 | Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function that fails to validate filesystem paths, allowing authenticated users to enumerate … | Aug 25, 2026 |
| CVE-2026-72696 | HIGH | 8.4 | Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile() that allows local attackers to overwrite arbitrary files by pre-creating symlinks at predictable … | Aug 25, 2026 |
| CVE-2026-72695 | HIGH | 8.1 | Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows authenticated users with media management permissions to delete arbitrary files by supplying filenames … | Aug 25, 2026 |
| CVE-2026-56710 | CRITICAL | 9.8 | Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can … | Aug 25, 2026 |
| CVE-2026-56709 | HIGH | 7.5 | Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to … | Aug 25, 2026 |
| CVE-2026-56708 | MEDIUM | 5.3 | Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delivery that allows attackers to bypass hostname validation by DNS rebinding. Attackers … | Aug 25, 2026 |
| CVE-2026-56707 | HIGH | 7.7 | Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode that allows users with page-edit access to render … | Aug 25, 2026 |
| CVE-2026-56706 | MEDIUM | 6.8 | Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value in every token (format (rand XOR secret):rand), … | Aug 25, 2026 |
| CVE-2026-56705 | CRITICAL | 9.8 | Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers … | Aug 25, 2026 |
| CVE-2026-56704 | MEDIUM | 6.1 | Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server … | Aug 25, 2026 |
| CVE-2026-56703 | HIGH | 7.2 | Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can … | Aug 25, 2026 |
| CVE-2026-56702 | HIGH | 8.8 | Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a … | Aug 25, 2026 |
| CVE-2026-34968 | HIGH | 8.1 | Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop action fails to validate file extensions before deletion. An … | Aug 25, 2026 |
| CVE-2026-34967 | MEDIUM | 5.4 | Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php. An authenticated user … | Aug 25, 2026 |
| CVE-2026-34964 | MEDIUM | 5.8 | Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, which only inspects leading integers for privileged ports and … | Aug 25, 2026 |
| CVE-2026-34959 | MEDIUM | 4.7 | Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no trusted-proxy check and no validation of the prefix value. An attacker can … | Aug 25, 2026 |
| CVE-2026-19801 | MEDIUM | 4.3 | The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnerable to authorization bypass in all versions up … | Aug 25, 2026 |
| CVE-2026-16434 | UNKNOWN | — | Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GHSA-8478-xrj3-h9c2). The validation guard (bootstrap.inc.php) only rejects prefixes matching … | Aug 25, 2026 |
| CVE-2026-15023 | MEDIUM | 6.5 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to generic SQL Injection via Stored 'meta_key' via Event/Location Duplicate Action … | Aug 25, 2026 |