Grav CMS 的 Comments 插件(getgrav/grav-plugin-comments)在 1.2.10 及更早版本中存在一个安全漏洞。该插件注册了一个管理员处理程序,该处理程序在未进行任何身份验证检查的情况下,以 JSON 格式返回评论数据。此处理程序根据 函数进行分支判断,但 仅表明当前路由上是否注册了管理员服务,并不能说明访问者是否已通过身份验证。该处理程序在插件阶段就会输出 JSON 数据并调用 ,此时经典的 Admin 插件尚未渲染其登录界面。 因此,在启用 Comments 插件(默认配
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| getgrav | grav-plugin-comments | 0 ~ 1.2.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100670 | 8.8 HIGH | Grav CMS 2.0.14 through 2.0.24 Privilege Escalation via Blueprint Guard Bypass |
| CVE-2026-100673 | 8.2 HIGH | Grav Data Manager before 1.4.5 Stored XSS via item-detail view |
| CVE-2026-100671 | 8.0 HIGH | Grav before 2.0.25 Session Cookie Theft via Twig Sandbox |
| CVE-2026-100669 | 7.5 HIGH | Grav before 2.0.25 Sensitive File Disclosure via Case-Variation Bypass |
| CVE-2026-100668 | 6.5 MEDIUM | Grav before 2.0.25 Sandbox Escape via array Filter |
| CVE-2026-100667 | 5.3 MEDIUM | grav-plugin-login 3.8.7 through 3.9.6 Two-Factor Authentication Bypass |
No comments yet