← Back to the live CVE advisory feed

CVE-2026-92916: Product identification pending

Severity
8.7 (HIGH)
Affected versions
Through 1.7.53.2
Fixed version
1.7.53.4
Patch status
Patched
Published
2026-09-17T12:18:30.710
Modified
2026-09-17T12:18:30.830

Why it matters

This matters because the affected product may be exposed on public websites. A vulnerable plugin can create a direct path to site compromise, malicious code deployment, or data theft.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Check whether the affected WordPress plugin or theme is installed.
  • Update, disable, or remove the affected component if present.
  • Compare installed versions against the affected version range in the advisory.
  • Review logs for suspicious activity related to the affected application or component.

Technical summary

Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled (system.debugger.enabled: true, which is not the default), the Clockwork profiler endpoint is exposed without authentication: InitializeProcessor::handleDebuggerRequest() intercepts any path containing /__clockwork/ during bootstrap and passes it to Debugger::debuggerRequest(), which performs no user lookup, IP restriction, or Clockwork authenticator check, and also supports anonymous pagination over the entire stored history. With the shipped censored: false default, each stored record contains raw request cookies (including Grav's session cookie, whose value is the PHP session id, allowing an attacker to resume another user's session, including an authenticated admin's), the full parsed request body (Grav's login form posts data[username]/data[password], so passwords are stored in plaintext because Clockwork's password filter only inspects top-level keys), and the site's entire system and plugin configuration, including operator-saved secrets such as SMTP credentials, third-party API keys, and licence keys. Authorization and X-API-Token headers are stored even when censored: true. On Grav 2.0, setting provider: debugbar does not avoid the issue because Grav forces the Clockwork provider for requests preferring a JSON response. The issue is fixed in 1.7.53.4 and 2.0.22, which restrict /__clockwork/ to server-local requests or requests presenting the new system.debugger.token secret and strip cookies and credential headers from stored records. Workarounds include setting debugger.enabled: false or blocking /__clockwork/ at the web server or CDN.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 18, 2026 12:00 AM UTC
1021 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-62104
Migratico Lite PATCH
Reporter: AUDIT
10
CRITICAL
VIEW RECORD
CVE-2026-92937
Product identification pending PATCH
Reporter: DISCLOSURE
10
CRITICAL
VIEW RECORD
CVE-2026-92940
Product identification pending PATCH
Reporter: DISCLOSURE
10
CRITICAL
VIEW RECORD
CVE-2026-92941
Product identification pending PATCH
Reporter: DISCLOSURE
10
CRITICAL
VIEW RECORD
CVE-2026-92946
Product identification pending PATCH
Reporter: DISCLOSURE
10
CRITICAL
VIEW RECORD
CVE-2026-92947
Product identification pending PATCH
Reporter: DISCLOSURE
10
CRITICAL
VIEW RECORD
CVE-2026-92955
Product identification pending PATCH
Reporter: DISCLOSURE
10
CRITICAL
VIEW RECORD
CVE-2026-92956
Product identification pending PATCH
Reporter: DISCLOSURE
10
CRITICAL
VIEW RECORD
CVE-2026-92960
Product identification pending PATCH
Reporter: DISCLOSURE
10
CRITICAL
VIEW RECORD
CVE-2026-54734
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
10
CRITICAL
VIEW RECORD
CVE-2026-69399
Product identification pending
Reporter: SECURE
10
CRITICAL
VIEW RECORD
CVE-2026-69865
Product identification pending
Reporter: SECURE
10
CRITICAL
VIEW RECORD
CVE-2026-70200
Product identification pending
Reporter: SECURE
10
CRITICAL
VIEW RECORD
CVE-2026-83944
Product identification pending
Reporter: SECURE
10
CRITICAL
VIEW RECORD
CVE-2026-85889
Product identification pending
Reporter: SECURE
10
CRITICAL
VIEW RECORD
CVE-2026-85885
Product identification pending
Reporter: SECURE
9.9
CRITICAL
VIEW RECORD
CVE-2026-87796
Multi Uploader for Gravity Forms
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-86707
Private Feed Key
Reporter: CONTACT
9.8
CRITICAL
VIEW RECORD
CVE-2026-86709
The Pressengine
Reporter: CONTACT
9.8
CRITICAL
VIEW RECORD
CVE-2026-86710
Login with QR
Reporter: CONTACT
9.8
CRITICAL
VIEW RECORD
CVE-2026-90822
Product identification pending
Reporter: CONTACT
9.8
CRITICAL
VIEW RECORD
CVE-2026-90823
Product identification pending
Reporter: CONTACT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62101
EduAdmin Booking PATCH
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62108
Headless Single Sign On PATCH
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-54617
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-54626
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-54627
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-45140
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-54460
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-54053
many-notes PATCH
Reporter: SECURITY-ADVISORIES
9.6
CRITICAL
VIEW RECORD
CVE-2026-54752
devicetype-library
Reporter: SECURITY-ADVISORIES
9.6
CRITICAL
VIEW RECORD
CVE-2026-87701
Product identification pending
Reporter: SECURE
9.6
CRITICAL
VIEW RECORD
CVE-2026-92934
Product identification pending PATCH
Reporter: DISCLOSURE
9.5
CRITICAL
VIEW RECORD
CVE-2026-92935
vm2 PATCH
Reporter: DISCLOSURE
9.5
CRITICAL
VIEW RECORD
CVE-2026-92860
Pulse
Reporter: CNA
9.4
CRITICAL
VIEW RECORD
CVE-2026-92938
Product identification pending PATCH
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-92939
Product identification pending PATCH
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-92948
vm2 PATCH
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-92951
Product identification pending PATCH
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-92957
Product identification pending PATCH
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-54618
obsidian-web-mcp PATCH
Reporter: SECURITY-ADVISORIES
9.4
CRITICAL
VIEW RECORD
CVE-2026-54501
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.4
CRITICAL
VIEW RECORD
CVE-2026-92944
Product identification pending
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-92950
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-92953
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-86863
pgAdmin 4 PATCH
Reporter: F86EF6DC-4D3A-42AD-8F28-E6D5547A5007
9.3
CRITICAL
VIEW RECORD
CVE-2026-54237
wavelog PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-70009
Product identification pending
Reporter: SECURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-15688
Product identification pending
Reporter: MITSUBISHIELECTRIC.PSIRT
9.2
CRITICAL
VIEW RECORD
CVE-2026-92954
Product identification pending PATCH
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-79752
cakephp PATCH
Reporter: SECURITY-ADVISORIES
9.2
CRITICAL
VIEW RECORD
CVE-2026-76834
Product identification pending
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-92943
Product identification pending PATCH
Reporter: FF89BA41-3AA1-4D27-914A-91399E9639E5
9.2
CRITICAL
VIEW RECORD
CVE-2026-93393
Product identification pending
Reporter: CNA
9.2
CRITICAL
VIEW RECORD
CVE-2026-92913
AVideo
Reporter: DISCLOSURE
9.1
CRITICAL
VIEW RECORD
CVE-2026-82761
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
9.1
CRITICAL
VIEW RECORD
CVE-2026-85500
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
9.1
CRITICAL
VIEW RECORD
CVE-2026-86533
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
9.1
CRITICAL
VIEW RECORD
CVE-2026-63472
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-88952
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
9.1
CRITICAL
VIEW RECORD
CVE-2026-91039
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
9.1
CRITICAL
VIEW RECORD
CVE-2026-54670
WeGIA PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-54767
WeGIA PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-76949
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
9.1
CRITICAL
VIEW RECORD
CVE-2026-88795
wpShopGermany IT-RECHT KANZLEI PATCH
Reporter: CONTACT
9
CRITICAL
VIEW RECORD
CVE-2026-47252
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9
CRITICAL
VIEW RECORD
CVE-2026-45143
chamilo-lms PATCH
Reporter: SECURITY-ADVISORIES
9
CRITICAL
VIEW RECORD
CVE-2026-77903
Product identification pending
Reporter: SECURE
9
CRITICAL
VIEW RECORD
CVE-2026-92952
Product identification pending PATCH
Reporter: DISCLOSURE
8.9
HIGH
VIEW RECORD
CVE-2026-25283
Product identification pending
Reporter: PRODUCT-SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-85130
Product identification pending PATCH
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2026-87786
Dewa Kirim
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2026-88792
Dictionary
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2026-88904
PuppyFW
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2026-86801
To Do List Member
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2026-14850
Product identification pending
Reporter: CVE-COORDINATION
8.8
HIGH
VIEW RECORD
CVE-2026-78295
Product identification pending
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-92972
Product identification pending
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-77614
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-28326
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-54239
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-54504
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-15815
Product identification pending
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-54916
Product identification pending
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-54519
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-54612
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-54671
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-92916
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-92917
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-92918
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-89418
Product identification pending
Reporter: CVE-COORDINATION
8.7
HIGH
VIEW RECORD
CVE-2026-92942
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-92961
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-92970
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-92971
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-63459
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-92983
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-92987
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-69197
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-86864
Product identification pending PATCH
Reporter: F86EF6DC-4D3A-42AD-8F28-E6D5547A5007
8.7
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.