CVE-2025-66301
- EPSS 1.36%
- Veröffentlicht 01.12.2025 21:30:43
- Zuletzt bearbeitet 26.09.2026 00:10:00
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an editor with only permissions to change basic content on the form is now a...
CVE-2025-66300
- EPSS 0.44%
- Veröffentlicht 01.12.2025 21:19:00
- Zuletzt bearbeitet 26.09.2026 00:10:00
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can read any server files using "Frontmatter" form. This includes Grav user account files (/grav/user/accounts/*.yaml), which store ha...
CVE-2025-66299
- EPSS 0.59%
- Veröffentlicht 01.12.2025 21:15:11
- Zuletzt bearbeitet 26.09.2026 00:10:00
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenticated user with editor permissions to execute arbitrary code on the remote server, bypassing the exis...
CVE-2025-66298
- EPSS 0.37%
- Veröffentlicht 01.12.2025 21:10:43
- Zuletzt bearbeitet 26.09.2026 00:10:00
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav configuration details (including plugin configuration details) by using the correct POST payload to exploit a Server-Side Template (SST)...
CVE-2025-66297
- EPSS 0.77%
- Veröffentlicht 01.12.2025 21:05:44
- Zuletzt bearbeitet 26.09.2026 00:10:00
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or edit pages in Grav CMS can enable Twig processing in the page frontmatter. By injecting malicious Twig expressions, the user can es...
CVE-2025-66296
- EPSS 0.31%
- Veröffentlicht 01.12.2025 21:03:07
- Zuletzt bearbeitet 26.09.2026 00:10:00
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin plugin due to the absence of username uniqueness validation when creating users. A user with the create user permission can create ...
CVE-2025-66294
- EPSS 2.86%
- Veröffentlicht 01.12.2025 20:52:08
- Zuletzt bearbeitet 26.09.2026 00:10:00
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor permissions to execute arbitrary commands on the server and, under certain...
CVE-2025-66295
- EPSS 0.54%
- Veröffentlicht 01.12.2025 20:46:56
- Zuletzt bearbeitet 26.09.2026 00:10:00
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new user through the Admin UI and supplies a username containing path traversal sequences (for example ..\Nijat or ../Nijat), Grav writes...
CVE-2025-63593
- EPSS 0.23%
- Veröffentlicht 03.11.2025 00:00:00
- Zuletzt bearbeitet 07.11.2025 18:33:34
Grav CMS1.7.49.5 is vulnerable to Cross Site Scripting (XSS).
CVE-2025-50286
- EPSS 9.32%
- Veröffentlicht 06.08.2025 00:00:00
- Zuletzt bearbeitet 07.11.2025 19:18:37
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct-install interface. Once uploaded, the plugin is automatically extracted and loaded, allowing arbitr...