Skip to content
June 25, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Data Leak
  • Gravatar data breach: affecting over 100 million users
  • Data Leak

Gravatar data breach: affecting over 100 million users

Do Son December 8, 2021 2 minutes read
Gravatar data breach
Add as a preferred
source on Google

Gravatar is one of the most well-known avatar websites in the world. The avatar set by the account created by the user here can be called for other websites without repeated settings. For example, WordPress supports the call of Gravatar avatars.

In fact, the Gravatar database was collected due to a vulnerability as early as October 2020. At that time, the database was traded on the dark web but did not attract much attention.

The main reason is that this database only contains the user’s registered email address, names, and usernames because Gravatar only needs these, so there is no private information at all except for the email address.

Firefox Monitor, a data breach monitoring platform of Mozilla, simply recorded this incident: the leaked Gravatar data only contained emails, names, and usernames.

Because there is no password and the password is not leaked, the user does not need to change the password. Moreover, even if the password is leaked, Gravatar will not cause potential threats.

However, it is recommended that users do not use repeated passwords, so as not to cause a more serious threat to all other websites due to the leakage of the password of one website.

The only threat to users is that they may receive various spam emails in the future because the database will definitely be used by spam gangs after it is widely circulated.

Related coverage

  • Report: 120,000 computers were infected with information-stealing malware
  • Fujitsu Discloses Data Breach, Customer and Personal Information Compromised
  • ZACROS Corporation Discloses Personal Information Leak Following Ransomware Attack
  • Architectural Exposure: Developers Extract Apple’s Subterranean Core Prompts for Siri AI
  • The Next.js Nightmare? Vercel Investigates “Critical” Internal Breach and Supply Chain Threat

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Gravatar data breach

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-34908CVSS 10.0
    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi...
  • CVE-2026-34909CVSS 10.0
    A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS...
  • CVE-2026-34910CVSS 10.0
    A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi...
  • CVE-2025-67038CVSS 9.8
    An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write...
  • CVE-2024-23692CVSS 9.8
    Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This...
  • CVE-2026-20230CVSS 8.6
    A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified...
  • CVE-2026-48907
    A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated...
  • CVE-2026-20253CVSS 9.8
    In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or...
  • CVE-2026-4020CVSS 7.5
    The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and...
  • CVE-2026-20182CVSS 10.0
    May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and...
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-55454CVSS 9.9
    Appsmith is a platform to build admin panels, internal tools, and dashboards....
  • CVE-2026-55570CVSS 9.0
    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it...
  • CVE-2026-50551CVSS 9.9
    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan...
  • CVE-2026-54158CVSS 9.9
    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the...
  • CVE-2026-52813CVSS 10.0
    Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization...
  • CVE-2026-52806CVSS 9.9
    Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs...
  • CVE-2026-45689CVSS 9.1
    Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0,...
  • CVE-2026-45688CVSS 9.1
    Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0,...
  • CVE-2026-54067CVSS 9.9
    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS...
  • CVE-2026-53943CVSS 9.6
    Ghost is a Node.js content management system. From until 6.37.0, when Ghost...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.