CVE-2026-63407 | GetGrav API Plugin up to 1.0.0-rc.15 CorsMiddleware cross-domain policy

SecurityVulns

A vulnerability categorized as problematic has been discovered in GetGrav API Plugin up to 1.0.0-rc.15. This vulnerability affects unknown code of the component CorsMiddleware. The manipulation results in permissive cross-domain policy with untrusted domains.

This vulnerability was named CVE-2026-63407. The attack may be performed from remote. There is no available exploit.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More