CVE-2025-66310 – Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` parameter `data[header][template]` in Advanced Tab
The following table lists the changes that have been made to the CVE-2025-66310 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-66308 – Grav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/config/site` parameter `data[taxonomies]`
The following table lists the changes that have been made to the CVE-2025-66308 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-66304 – Grav Exposes Password Hashes Leading to privilege escalation
The following table lists the changes that have been made to the CVE-2025-66304 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-66309 – Grav vulnerable to Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter data[header][content][items], located in the “Blog Config” tab
The following table lists the changes that have been made to the CVE-2025-66309 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-66307 – Grav Admin Plugin vulnerable to User Enumeration & Email Disclosure
The following table lists the changes that have been made to the CVE-2025-66307 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-66306 – Grav vulnerable to Information Disclosure via IDOR in Grav Admin Panel
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Panel which allows low-privilege users to access sensitive information from other accounts. Although direct account takeover is not possible, admin email addresses and other metadata can be exposed, increasing the risk of […]
CVE-2025-66305 – Grav vulnerable to Denial of Service via Improper Input Handling in ‘Supported’ Parameter
The following table lists the changes that have been made to the CVE-2025-66305 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-66303 – Grav is vulnerable to a DOS on the admin panel
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A Denial of Service (DoS) vulnerability has been identified in Grav related to the handling of scheduled_at parameters. Specifically, the application fails to properly sanitize input for cron expressions. By manipulating the scheduled_at parameter with a malicious input, such as a single quote, the application admin […]
CVE-2025-66302 – Grav vulnerable to Path Traversal allowing server files backup
The following table lists the changes that have been made to the CVE-2025-66302 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-66301 – Grav ihas Broken Access Control which allows an Editor to modify the page’s YAML Frontmatter to alter form processing actions
The following table lists the changes that have been made to the CVE-2025-66301 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]