Trilby Media Flex Objects Plugin是Trilby Media组织的一款灵活对象管理插件。 Trilby Media Flex Objects Plugin 1.4.3之前版本存在授权问题漏洞,该漏洞源于requireFlexPermission()方法在目录蓝图省略config.admin.permissions时未拒绝访问,可能导致经过身份验证的攻击者利用仅具有api.access的账户执行index、show、create、update、delete、export和med
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| getgrav | grav-plugin-flex-objects | < 1.4.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| getgrav | grav-plugin-flex-objects | < 1.4.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-62668 | 9.4 CRITICAL | Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols |
| CVE-2026-62666 | 8.8 HIGH | Grav API Plugin: non-super api.users.write manager -> super-admin via createApiKey (incomp |
| CVE-2026-64850 | 8.7 HIGH | Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData() |
| CVE-2026-64852 | 8.7 HIGH | Grav API Plugin: Missing authorization on API-key generate/revoke lets any admin.login use |
| CVE-2026-64851 | 8.5 HIGH | Grav Shortcode Core Plugin: Stored XSS in shortcode-core attribute handlers |
| CVE-2026-62673 | 8.2 HIGH | Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesys |
| CVE-2026-63407 | 8.2 HIGH | Grav API Plugin: CORS 'Access-Control-Allow-Origin: *' on Authenticated API Responses |
| CVE-2026-62667 | 8.1 HIGH | Grav API Plugin : API Key 'scopes' Never Enforced - Delegated Least-Privilege Keys Carry F |
| CVE-2026-63408 | 7.5 HIGH | Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parameter |
| CVE-2026-62669 | 7.4 HIGH | Grav Login Plugin: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pen |
| CVE-2026-61690 | 6.5 MEDIUM | Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limits |
| CVE-2026-61842 | 6.5 MEDIUM | Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 by |
| CVE-2026-62672 | 6.0 MEDIUM | Grav: Authenticated ReDoS via regex_replace in Twig Sandbox |
| CVE-2026-62671 | 5.4 MEDIUM | CSRF in grav-plugin-login: anonymous attacker rotates a logged-in user's 2FA (TOTP) secret |
| CVE-2026-53654 | 5.3 MEDIUM | Grav: Unauthenticated open redirect via login twofa_cancel _redirect |
| CVE-2026-61607 | 4.6 MEDIUM | Grav API Plugin: Stored XSS via SVG Upload - API Media Pipeline Bypasses Sanitizer |
No comments yet