PT-2025-48569 · Unknown+1 · Grav Admin Plugin+1
Published
2025-12-01
·
Updated
2025-12-04
·
CVE-2025-66310
CVSS v4.0
6.2
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Grav versions prior to 1.11.0-beta.1
Description
The Grav admin plugin, an HTML user interface for configuring Grav and managing pages, contains a Stored Cross-Site Scripting (XSS) issue. An attacker can inject malicious scripts into the
data[header][template] parameter of the /admin/pages/[page] API endpoint. The injected script is stored in the page's frontmatter and automatically executed when the content is rendered in the administrative interface or frontend view.Recommendations
Update to Grav version 1.11.0-beta.1 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav
Grav Admin Plugin