<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 18:53:53 +0000</lastBuildDate>
    <item>
      <title>cnvd-2025-30340</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2025-30340</link>
      <description>cnvd-2025-30340</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2025-30340</guid>
    </item>
    <item>
      <title>EUVD-2026-262341</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-262341</link>
      <description>EUVD-2026-262341</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-262341</guid>
    </item>
    <item>
      <title>fkie_cve-2025-66307</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-66307</link>
      <description>&lt;p&gt;This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a user enumeration and email disclosure vulnerability exists in Grav. The &amp;#34;Forgot Password&amp;#34; functionality at /admin/forgot leaks information about valid usernames and their associated email addresses through distinct server responses. This allows an attacker to enumerate users and disclose sensitive email addresses, which can be leveraged for targeted attacks such as password spraying, phishing, or social engineering. This vulnerability is fixed in 1.11.0-beta.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a user enumeration and email disclosure vulnerability exists in Grav. The &amp;#34;Forgot Password&amp;#34; functionality at /admin/forgot leaks information about valid usernames and their associated email addresses through distinct server responses. This allows an attacker to enumerate users and disclose sensitive email addresses, which can be leveraged for targeted attacks such as password spraying, phishing, or social engineering. This vulnerability is fixed in 1.11.0-beta.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-66307</guid>
    </item>
    <item>
      <title>GHSA-q3qx-cp62-f6m7 — Grav Admin Plugin vulnerable to User Enumeration &amp; Email Disclosure</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q3qx-cp62-f6m7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: getgrav/grav&lt;/p&gt;
&lt;p&gt;# Grav v1.7.49.5 / Admin v1.10.49.1 – User Enumeration &amp;amp; Email Disclosure&lt;/p&gt;
&lt;p&gt;### Summary
A **user enumeration and email disclosure vulnerability** exists in Grav **v1.7.49.5** with Admin plugin **v1.10.49.1**.  
The &amp;#34;Forgot Password&amp;#34; functionality at `/admin/forgot` leaks information about valid usernames and their associated email addresses through distinct server responses.  
This allows an attacker to enumerate users and disclose sensitive email addresses, which can be leveraged for targeted attacks such as password spraying, phishing, or social engineering.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The issue resides in the [`taskForgot()`](https://github.com/getgrav/grav-plugin-admin/blob/6d673fc7c4f6962756f93ae651371e81f7f20924/classes/plugin/Controllers/Login/LoginController.php#L349) function, which handles the forgot password workflow.  
Relevant vulnerable logic:&lt;/p&gt;
&lt;p&gt;```php
if (null === $user || $user-&amp;gt;state !== &amp;#39;enabled&amp;#39; || !$to) {
    ...
    // Generic message for invalid/non-existing users
    $this-&amp;gt;setMessage($this-&amp;gt;translate(&amp;#39;PLUGIN_ADMIN.FORGOT_INSTRUCTIONS_SENT_VIA_EMAIL&amp;#39;));
    return $this-&amp;gt;createRedirectResponse($current);
}&lt;/p&gt;
&lt;p&gt;if ($rateLimiter-&amp;gt;isRateLimited($username)) {
    ...
    $interval = $config-&amp;gt;get(&amp;#39;plugins.login.max_pw_resets_interval&amp;#39;, 2);&lt;/p&gt;
&lt;p&gt;// Sensitive message for valid users
    $this-&amp;gt;setMessage($this-&amp;gt;translate(&amp;#39;PLUGIN_LOGIN.FORGOT_CANNOT_RESET_IT_IS_BLOCKED&amp;#39;, $to, $interval), &amp;#39;error&amp;#39;);&lt;/p&gt;
&lt;p&gt;return $this-&amp;gt;createRedirectResponse($current);
}
```&lt;/p&gt;
&lt;p&gt;When an attacker sub…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: getgrav/grav&lt;/p&gt;
&lt;p&gt;# Grav v1.7.49.5 / Admin v1.10.49.1 – User Enumeration &amp;amp; Email Disclosure&lt;/p&gt;
&lt;p&gt;### Summary
A **user enumeration and email disclosure vulnerability** exists in Grav **v1.7.49.5** with Admin plugin **v1.10.49.1**.  
The &amp;#34;Forgot Password&amp;#34; functionality at `/admin/forgot` leaks information about valid usernames and their associated email addresses through distinct server responses.  
This allows an attacker to enumerate users and disclose sensitive email addresses, which can be leveraged for targeted attacks such as password spraying, phishing, or social engineering.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The issue resides in the [`taskForgot()`](https://github.com/getgrav/grav-plugin-admin/blob/6d673fc7c4f6962756f93ae651371e81f7f20924/classes/plugin/Controllers/Login/LoginController.php#L349) function, which handles the forgot password workflow.  
Relevant vulnerable logic:&lt;/p&gt;
&lt;p&gt;```php
if (null === $user || $user-&amp;gt;state !== &amp;#39;enabled&amp;#39; || !$to) {
    ...
    // Generic message for invalid/non-existing users
    $this-&amp;gt;setMessage($this-&amp;gt;translate(&amp;#39;PLUGIN_ADMIN.FORGOT_INSTRUCTIONS_SENT_VIA_EMAIL&amp;#39;));
    return $this-&amp;gt;createRedirectResponse($current);
}&lt;/p&gt;
&lt;p&gt;if ($rateLimiter-&amp;gt;isRateLimited($username)) {
    ...
    $interval = $config-&amp;gt;get(&amp;#39;plugins.login.max_pw_resets_interval&amp;#39;, 2);&lt;/p&gt;
&lt;p&gt;// Sensitive message for valid users
    $this-&amp;gt;setMessage($this-&amp;gt;translate(&amp;#39;PLUGIN_LOGIN.FORGOT_CANNOT_RESET_IT_IS_BLOCKED&amp;#39;, $to, $interval), &amp;#39;error&amp;#39;);&lt;/p&gt;
&lt;p&gt;return $this-&amp;gt;createRedirectResponse($current);
}
```&lt;/p&gt;
&lt;p&gt;When an attacker sub…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q3qx-cp62-f6m7</guid>
    </item>
  </channel>
</rss>
