grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An authenticated low-privileged user with permission to edit content can inject malicious JavaScript payloads into editable fields. The payload is stored on the server and later executed when any other user views or edits the affected page.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/Yohane-Mashiro/grav_cve/issues/1 |
|
History
Mon, 15 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getgrav
Getgrav grav |
|
| Vendors & Products |
Getgrav
Getgrav grav |
Mon, 15 Dec 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An authenticated low-privileged user with permission to edit content can inject malicious JavaScript payloads into editable fields. The payload is stored on the server and later executed when any other user views or edits the affected page. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-15T15:45:59.621Z
Reserved: 2025-12-08T00:00:00.000Z
Link: CVE-2025-66843
No data.
Status : Awaiting Analysis
Published: 2025-12-15T16:15:53.387
Modified: 2025-12-15T18:22:13.783
Link: CVE-2025-66843
No data.
OpenCVE Enrichment
Updated: 2025-12-15T21:33:36Z