CVE intelligence

CVE-2026-86196

Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing u

Published 2026-09-05 · CVSS

high

NIST record