PT-2025-48711 · Grav Cms · Grav Cms

Published

2025-12-02

·

Updated

2025-12-02

·

CVE-2025-65186

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Grav CMS version 1.7.49
Description Grav CMS version 1.7.49 is susceptible to Cross Site Scripting (XSS). Authenticated users can edit page content using a Markdown editor. This editor does not adequately sanitize <script> tags, enabling the injection of stored XSS payloads. These payloads execute when pages are viewed within the admin interface. The vulnerable component is the page editor.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-65186
GHSA-CCHQ-397M-Q2QM

Affected Products

Grav Cms