MEDIUMVulnerability

CVE-2026-72699

The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register() method in classes/Login.php throws a distinct exception (EMAIL_NOT_AVAILABLE) when a submitted email address already belongs to an existing account, while allowing registration to proceed otherwise. Because the registration endpoint has no rate limiting, an attacker can enumerate which email addresses have accounts on the site, one guess per request.

Properties

severity
MEDIUM
score
5.3
cve_id
CVE-2026-72699
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
published_at
2026-08-25T02:16:45.687
last_modified
2026-08-31T20:52:56.343

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Observable Discrepancy

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72699 — Ninja Signal Threat Intelligence | Ninja Signal