All 1 CVE vulnerabilities found in grav-plugin-login, with AI-generated Chinese analysis, references, and POCs.
Vendor: getgrav
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-62671 | CSRF in grav-plugin-login: anonymous attacker rotates a logged-in user's 2FA (TOTP) secret (no nonce on task=login.regenerate2FASecret) CWE-352 | 5.4 | Medium | 2026-08-19 |
All 1 known CVE vulnerabilities affecting grav-plugin-login with full Chinese analysis, references, and POCs where available.