Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100672— grav-plugin-comments before 1.2.11 Unauthenticated Information Disclosure

Quick assessment

Affected
getgrav grav-plugin-comments
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Grav CMS 的 Comments 插件(getgrav/grav-plugin-comments)在 1.2.10 及更早版本中存在一个安全漏洞。该插件注册了一个管理员处理程序,该处理程序在未进行任何身份验证检查的情况下,以 JSON 格式返回评论数据。此处理程序根据 函数进行分支判断,但 仅表明当前路由上是否注册了管理员服务,并不能说明访问者是否已通过身份验证。该处理程序在插件阶段就会输出 JSON 数据并调用 ,此时经典的 Admin 插件尚未渲染其登录界面。 因此,在启用 Comments 插件(默认配

CVSS 7.5 · High EPSS 0.45% · P36

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100672

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
grav-plugin-comments before 1.2.11 Unauthenticated Information Disclosure
Source: CVE Program / CVE List V5
Vulnerability Description
The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that returns comment data as JSON without any authentication check. The handler branches on isAdmin(), which only indicates that the admin service is registered on the current route rather than that the visitor is authenticated, and it echoes the JSON and calls exit() during the plugins stage, before the classic Admin plugin would render its login screen. On a site using the classic Admin plugin with Comments enabled (the default), an unauthenticated remote attacker can request /admin/comments/page:<n> (e.g. page:0.001) and retrieve every comment from the last 7 days, including each commenter's email address and the absolute server filesystem path of the data file. Sites running the Grav 2.0 Admin Next stack (admin2 + api) are not affected via this path. The issue is fixed in 1.2.11, which requires an authenticated user with admin.comments or admin.super and removes the absolute filePath from the response.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
getgrav grav-plugin-comments 0 ~ 1.2.11 -

II. Public POCs for CVE-2026-100672

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100672

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100672 (1)

Other References for CVE-2026-100672 (1)

Same Patch Batch · getgrav · 2026-09-26 · 7 CVEs total

CVE-2026-100670 8.8 HIGH Grav CMS 2.0.14 through 2.0.24 Privilege Escalation via Blueprint Guard Bypass
CVE-2026-100673 8.2 HIGH Grav Data Manager before 1.4.5 Stored XSS via item-detail view
CVE-2026-100671 8.0 HIGH Grav before 2.0.25 Session Cookie Theft via Twig Sandbox
CVE-2026-100669 7.5 HIGH Grav before 2.0.25 Sensitive File Disclosure via Case-Variation Bypass
CVE-2026-100668 6.5 MEDIUM Grav before 2.0.25 Sandbox Escape via array Filter
CVE-2026-100667 5.3 MEDIUM grav-plugin-login 3.8.7 through 3.9.6 Two-Factor Authentication Bypass

IV. Related Vulnerabilities

V. Comments for CVE-2026-100672

No comments yet


Leave a comment