CVE-2026-75833 | GetGrav up to 1.0.13 SSO Controller sanitizeReturnTo returnTo redirect

SecurityVulns

A vulnerability labeled as problematic has been found in GetGrav Grav up to 1.0.13. This vulnerability affects the function SsoController::sanitizeReturnTo of the component SSO Controller. The manipulation of the argument returnTo results in open redirect.

This vulnerability was named CVE-2026-75833. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded.VulDB Recent EntriesRead More