PT-2026-99343 · Grav Cms · Comments Plugin

·

CVE-2026-100672

·

Published

2026-09-26

·

Updated

2026-09-27

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions getgrav/grav-plugin-comments versions prior to 1.2.11
Description The Comments plugin for Grav CMS registers an admin handler that returns comment data as JSON without performing an authentication check. The handler relies on the isAdmin() function, which only verifies if the admin service is registered on the current route instead of confirming the visitor's authentication status. This allows an unauthenticated remote attacker to access the /admin/comments/page:<n> endpoint and retrieve comments from the last 7 days, including commenter email addresses and the absolute server filesystem path of the data file. This issue affects sites using the classic Admin plugin with Comments enabled.
Recommendations Update to version 1.2.11.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100672

Affected Products

Comments Plugin