Grav CMS 的 Login 插件(grav-plugin-login)在版本 >= 3.8.7 且 < 3.9.7 中存在一个安全漏洞,允许绕过基于双重身份验证(2FA)的挑战机制。具体而言,当内容受 Twig 函数 或短代码 控制时,该漏洞可能导致 2FA 防护被绕过。 在启用了 2FA 的站点上, 方法仅检查会话中表明密码验证步骤已成功完成的标志,而未验证表示整个登录过程已彻底完成的标志。因此,处于 2FA 验证码输入提示阶段的会话仍被视为完全认证。攻击者即使仅掌握会员的密码而无法响应第二因素验证,仍可读
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100670 | 8.8 HIGH | Grav CMS 2.0.14 through 2.0.24 Privilege Escalation via Blueprint Guard Bypass |
| CVE-2026-100673 | 8.2 HIGH | Grav Data Manager before 1.4.5 Stored XSS via item-detail view |
| CVE-2026-100671 | 8.0 HIGH | Grav before 2.0.25 Session Cookie Theft via Twig Sandbox |
| CVE-2026-100669 | 7.5 HIGH | Grav before 2.0.25 Sensitive File Disclosure via Case-Variation Bypass |
| CVE-2026-100672 | 7.5 HIGH | grav-plugin-comments before 1.2.11 Unauthenticated Information Disclosure |
| CVE-2026-100668 | 6.5 MEDIUM | Grav before 2.0.25 Sandbox Escape via array Filter |
No comments yet