Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/getgrav/grav-plugin-api

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.8, the Grav API plugin intercepts the apiKeyGenerate and apiKeyRevoke admin tasks in user/plugins/api/api.php and authorizes the caller with only admin.login. A basic panel user can select another account from the route, create a persistent ApiKeyManager credential bound to that target, and inherit the target's API permissions, including api.super or administrative write access when present. This issue is fixed in version 1.0.8.

Join the discussion

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0-rc.16, the Grav API plugin JwtAuthenticator::extractBearerToken() accepts a JWT from the token URL query parameter on every /api/v1 route, including state-changing endpoints. Request URLs consequently expose valid access tokens through Apache, proxy, and CDN logs, browser history, and Referer headers, allowing a party with access to those records to reuse the token with the owner's API privileges. This issue is fixed in version 1.0.0-rc.16.

Join the discussion

CVE-2026-63407 is a high-severity vulnerability in the Grav API Plugin for Grav CMS. Prior to version 1.0.0-rc.16, the plugin's CORS middleware allowed any origin to access authenticated API endpoints by returning Access-Control-Allow-Origin: *. This permissive cross-domain policy enables JavaScript from any origin to submit attacker-obtained JWT tokens and perform actions with the token owner's privileges, including reading data and modifying accounts. The issue is fixed in version 1.0.0-rc.16.

Join the discussion

CVE-2026-62667 is a missing authorization vulnerability in the Grav API Plugin for Grav CMS versions prior to 1.0.6. The flaw allows an API key issued with limited scopes to bypass scope restrictions and perform all actions available to the owning user, including write, delete, and administrative operations. This occurs because the authentication process does not properly enforce declared scopes, leading to excessive permissions. The issue is fixed in version 1.0.6.

Join the discussion

A vulnerability in Grav API Plugin prior to version 1.0.6 allows a non-super user with api.users.write permission to create an API key with super-administrator privileges. This occurs because certain user mutation endpoints omit a critical access check, enabling unauthorized privilege escalation and manipulation of two-factor authentication settings. The issue is fixed in version 1.0.6.

Join the discussion

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API plugin WebhookController.php accepts webhook URLs after only FILTER_VALIDATE_URL syntax validation, and WebhookDispatcher.php initializes cURL without CURLOPT_PROTOCOLS or CURLOPT_REDIR_PROTOCOLS restrictions. An account with api.webhooks.write can submit file, dict, gopher, private-network, or link-local targets, retrieve local files and delivery response bodies, and pivot requests to internal services or cloud metadata endpoints. This issue is fixed in version 1.0.6.

Join the discussion

CVE-2026-61607 is a cross-site scripting (XSS) vulnerability in the Grav API Plugin for Grav CMS. Versions prior to 1.0.2 do not properly sanitize SVG files uploaded via the POST /api/v1/media endpoint, allowing attackers with api.media.write permission to upload SVGs containing malicious JavaScript. When these SVG files are served with the image/svg+xml content type, the embedded script executes in the victim's browser, potentially leading to session data theft and unauthorized actions. This vulnerability is fixed in version 1.0.2.

Join the discussion
0

CVE-2026-75832 is a critical missing authorization vulnerability in the Grav API plugin (getgrav/grav-plugin-api) before version 1.0.15. The flaw exists in the BlueprintPathResolver::resolveUserScope() method, which incorrectly authorizes access based on the super-admin ACL flag of the account rather than the actual API key scope. This allows an attacker with an API key scoped only to api.media.write but minted on a super-admin account to write files into another user's scope and browse that user's file listings, despite lacking explicit api.users.write permissions.

Join the discussion

A path traversal vulnerability exists in grav-plugin-api versions from 0 up to 1.0.14 in the PagesController::batchCopy() method. Authenticated users with editor-level permissions can exploit this flaw by supplying crafted path traversal sequences in the 'suffix' parameter to write arbitrary files outside the intended directory. This vulnerability allows unauthorized file writes to locations writable by the web server. The issue is fixed in version 1.0.15.

Join the discussion

CVE-2026-75829 is a high-severity vulnerability in the grav-plugin-api component of the getgrav grav CMS. Versions before 1.0.15 do not properly validate Twig template content submitted via the translate() endpoint. This allows attackers with api.pages.write permission to inject server-side template code that is executed when the page is rendered.

Join the discussion

Showing 1 to 10 of 19 results

Filters:Package: pkg:github/getgrav/grav-plugin-api
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses