Executive brief
The Comments plugin for Grav CMS, a content management system for building websites, allows unauthenticated visitors to retrieve sensitive comment data including commenter email addresses and server file paths by accessing a specific admin endpoint. An attacker can exploit this without any credentials or special access to harvest private information about site visitors. This data exposure could aid further attacks against website users and administrators.
Technical details
The plugin's admin handler checks isAdmin() to verify the admin service is registered—not that the user is authenticated—and returns comment data as JSON via the /admin/comments/page endpoint before the Admin plugin's authentication layer runs. The vulnerability exploits the Grav plugin initialization order: the Comments handler branches on service presence rather than session authentication, calls exit() to bypass further processing, and includes plaintext email addresses and absolute filesystem paths in its JSON response. The fix in version 1.2.11 adds proper authentication checks for admin.comments or admin.super permissions and removes the filePath field.
Affected products
- Grav Comments plugin through 1.2.10
Timeline
- 2026-09-26: disclosed
- 2026-09-26: patched: version 1.2.11 released