CVE-2025-66300 – Grav is vulnerable to Arbitrary File Read

The following table lists the changes that have been made to the CVE-2025-66300 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]

CVE-2025-66298 – Grav is vulnerable to Server-Side Template Injection (SSTI) via Forms

The following table lists the changes that have been made to the CVE-2025-66298 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]

CVE-2025-65622 – Snipe-IT Stored Cross-Site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-65622 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]

CVE-2025-66313 – ChurchCRM vulnerable to a time-based blind SQL injection via the 1FieldSec parameter

The following table lists the changes that have been made to the CVE-2025-66313 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]

CVE-2025-66297 – Grav vulnerable to Privilege Escalation and Authenticated Remote Code Execution via Twig Injection

The following table lists the changes that have been made to the CVE-2025-66297 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]

CVE-2025-66296 – Grav vulnerable to Privilege Escalation in Grav Admin: Missing Username Uniqueness Check Allows Admin Account Takeover

The following table lists the changes that have been made to the CVE-2025-66296 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]

CVE-2025-66294 – Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass

The following table lists the changes that have been made to the CVE-2025-66294 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]

CVE-2025-66206 – Frappe vulnerable to a path traversal allowing reading certain files

The following table lists the changes that have been made to the CVE-2025-66206 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]