PT-2025-30915 · Grav · Grav

Rapid-Echo

·

Published

2025-07-25

·

Updated

2025-08-15

·

CVE-2025-46199

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions grav versions prior to 1.7.49
Description A Cross Site Scripting issue exists in grav versions prior to 1.7.49. This allows an attacker to execute arbitrary code via a crafted script to the form fields.
Recommendations Update to grav version 1.7.49 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-46199

Affected Products

Grav