在 1.0.20 版本之前的 Grav API 插件中,在“忘记密码”(forgot-password)端点中,密码重置链接是从不可信的 请求头构建的。这使得未经身份验证的攻击者能够将重置令牌重定向到攻击者控制的域名。攻击者可以针对任意账户发送带有恶意 头的密码重置请求,从受害者收到的邮件中截获重置令牌,从而完成账户接管,甚至包括超级管理员账户。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| getgrav | grav-plugin-api | < 1.0.20 |
affected |
1.0.20 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| getgrav | grav-plugin-api | 0 ~ 1.0.20 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86195 | 8.7 HIGH | grav-plugin-api 1.0.0 through 1.0.19 Privilege Escalation via Dot-Keyed Super Flag |
| CVE-2026-86193 | 8.7 HIGH | Grav API Plugin Authentication Bypass via Group-Inherited Super |
| CVE-2026-86194 | 6.9 MEDIUM | Grav Form Plugin before 9.1.22 Cross-Page Form Execution |
| CVE-2026-86197 | 5.1 MEDIUM | Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox |
No comments yet