PT-2025-51240 · Grav · Grav

Yohane-Mashiro

·

Published

2025-12-15

·

Updated

2025-12-17

·

CVE-2025-66843

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions grav versions prior to 1.7.49.5
Description The software contains a Stored Cross-Site Scripting issue within the page editing functionality. An authenticated, low-privileged user who has permission to edit content can inject malicious JavaScript payloads into editable fields. This payload is stored on the server and executed when another user views or edits the affected page.
Recommendations Update to version 1.7.49.5 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-66843
GHSA-MH85-44C2-3M97

Affected Products

Grav