Phishing Vulnerability in Grav Login Plugin for Web Platforms
CVE-2026-53654
5.3MEDIUM
What is CVE-2026-53654?
The Grav Login plugin prior to version 3.8.5 allows an unauthenticated attacker to manipulate the _redirect parameter. This lack of nonce protection permits setting arbitrary external redirects, enabling phishing attacks from a trusted Grav host. A successful attack could deceive users into divulging sensitive information. This vulnerability has been resolved in version 3.8.5.
Affected Version(s)
grav < 3.8.5
