vulnti.work

Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and u…

Low CVSS 1.8
CVECVE-2025-64059
First seen2026-09-16 15:16 UTC
Disclosed2026-09-13 19:16 UTC
Last updated2026-09-16 15:16 UTC
Channel statusauto

Summary

Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.

In-depth triage

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD