Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 27 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and redirect users to attacker-controlled domains, bypassing the require_trusted_host protection which only covers password reset flows. | |
| Title | Grav before 3.9.2 Host Header Injection via sendInvitationEmail | |
| First Time appeared |
Getgrav
Getgrav grav |
|
| Weaknesses | CWE-350 | |
| CPEs | cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Getgrav
Getgrav grav |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-26T16:12:46.333Z
Reserved: 2026-06-22T18:48:27.060Z
Link: CVE-2026-56709
Updated: 2026-08-26T15:58:35.771Z
Status : Received
Published: 2026-08-25T02:16:42.930
Modified: 2026-08-26T17:17:08.270
Link: CVE-2026-56709
No data.
OpenCVE Enrichment
Updated: 2026-08-25T05:30:16Z