PT-2025-48569 · Unknown+1 · Grav Admin Plugin+1

Published

2025-12-01

·

Updated

2025-12-04

·

CVE-2025-66310

CVSS v4.0

6.2

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Grav versions prior to 1.11.0-beta.1
Description The Grav admin plugin, an HTML user interface for configuring Grav and managing pages, contains a Stored Cross-Site Scripting (XSS) issue. An attacker can inject malicious scripts into the data[header][template] parameter of the /admin/pages/[page] API endpoint. The injected script is stored in the page's frontmatter and automatically executed when the content is rendered in the administrative interface or frontend view.
Recommendations Update to Grav version 1.11.0-beta.1 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-66310
GHSA-7G78-5G5G-MVFJ

Affected Products

Grav
Grav Admin Plugin