CVE-2025-66311
- EPSS 0.21%
- Veröffentlicht 01.12.2025 22:05:17
- Zuletzt bearbeitet 26.09.2026 00:10:00
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/[pa...
CVE-2025-66310
- EPSS 0.21%
- Veröffentlicht 01.12.2025 22:04:09
- Zuletzt bearbeitet 03.12.2025 21:56:30
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/[pa...
CVE-2025-66309
- EPSS 0.23%
- Veröffentlicht 01.12.2025 22:02:50
- Zuletzt bearbeitet 03.12.2025 21:56:35
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Reflected Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/...
CVE-2025-66308
- EPSS 0.21%
- Veröffentlicht 01.12.2025 22:00:42
- Zuletzt bearbeitet 03.12.2025 21:56:43
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/config/si...
CVE-2025-66307
- EPSS 0.31%
- Veröffentlicht 01.12.2025 21:53:43
- Zuletzt bearbeitet 26.09.2026 00:10:00
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a user enumeration and email disclosure vulnerability exists in Grav. The "Forgot Passwo...
CVE-2025-66306
- EPSS 0.29%
- Veröffentlicht 01.12.2025 21:46:00
- Zuletzt bearbeitet 26.09.2026 00:10:00
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Panel which allows low-privilege users to access sensitive information from other accounts. Although di...
CVE-2025-66305
- EPSS 0.38%
- Veröffentlicht 01.12.2025 21:43:29
- Zuletzt bearbeitet 03.12.2025 18:50:11
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Denial of Service (DoS) vulnerability was identified in the "Languages" submenu of the Grav admin configuration panel (/admin/config/system). Specifically, the Supported parameter fails to ...
CVE-2025-66304
- EPSS 0.4%
- Veröffentlicht 01.12.2025 21:40:11
- Zuletzt bearbeitet 26.09.2026 00:10:00
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section of the admin panel can view the password hashes of all users, including the admin user. This exposure can potentially lead to pri...
CVE-2025-66303
- EPSS 0.38%
- Veröffentlicht 01.12.2025 21:35:47
- Zuletzt bearbeitet 26.09.2026 00:10:00
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A Denial of Service (DoS) vulnerability has been identified in Grav related to the handling of scheduled_at parameters. Specifically, the application fails to properly sanitize input for cron...
CVE-2025-66302
- EPSS 0.47%
- Veröffentlicht 01.12.2025 21:33:40
- Zuletzt bearbeitet 26.09.2026 00:10:00
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CMS, allowing authenticated attackers with administrative privileges to read arbitrary files on the underlying server filesystem. Th...