Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 25 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register() method in classes/Login.php throws a distinct exception (EMAIL_NOT_AVAILABLE) when a submitted email address already belongs to an existing account, while allowing registration to proceed otherwise. Because the registration endpoint has no rate limiting, an attacker can enumerate which email addresses have accounts on the site, one guess per request. | |
| Title | Grav Login Plugin before 3.9.1 Email Enumeration via Registration | |
| First Time appeared |
Getgrav
Getgrav grav |
|
| Weaknesses | CWE-203 | |
| CPEs | cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Getgrav
Getgrav grav |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T15:26:33.287Z
Reserved: 2026-08-10T13:02:20.829Z
Link: CVE-2026-72699
Updated: 2026-08-25T15:26:29.101Z
Status : Received
Published: 2026-08-25T02:16:45.687
Modified: 2026-08-25T16:17:25.570
Link: CVE-2026-72699
No data.
OpenCVE Enrichment
Updated: 2026-08-25T06:00:04Z