CVE-2026-61451 — Grav: The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the
The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoint. The sanitizeHttpUrl() function only checks that the URL scheme is http/https and never verifies the host against the server's own origin, so an attacker can supply an arbitrary host. As a result, an unauthenticated attacker can cause the password reset email sent to a victim to contain a reset link point CVSSv3.1 9.6 (CRITICAL)