CVE-2025-66300 – Grav is vulnerable to Arbitrary File Read
The following table lists the changes that have been made to the CVE-2025-66300 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-66299 – Security Sandbox Bypass with SSTI (Server Side Template Injection) in the Grav CMS
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenticated user with editor permissions to execute arbitrary code on the remote server, bypassing the existing security sandbox. Since the security sandbox does not fully protect the Twig object, it is possible to […]
CVE-2025-66298 – Grav is vulnerable to Server-Side Template Injection (SSTI) via Forms
The following table lists the changes that have been made to the CVE-2025-66298 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-65622 – Snipe-IT Stored Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2025-65622 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-66313 – ChurchCRM vulnerable to a time-based blind SQL injection via the 1FieldSec parameter
The following table lists the changes that have been made to the CVE-2025-66313 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-66297 – Grav vulnerable to Privilege Escalation and Authenticated Remote Code Execution via Twig Injection
The following table lists the changes that have been made to the CVE-2025-66297 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-66296 – Grav vulnerable to Privilege Escalation in Grav Admin: Missing Username Uniqueness Check Allows Admin Account Takeover
The following table lists the changes that have been made to the CVE-2025-66296 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-66294 – Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass
The following table lists the changes that have been made to the CVE-2025-66294 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-66295 – Grav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System Corruption
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new user through the Admin UI and supplies a username containing path traversal sequences (for example ..Nijat or ../Nijat), Grav writes the account YAML file to an unintended path outside user/accounts/. The written YAML can contain […]
CVE-2025-66206 – Frappe vulnerable to a path traversal allowing reading certain files
The following table lists the changes that have been made to the CVE-2025-66206 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]