SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2025-64059

LOW · CVSS 1.8 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects Grav 1.7.50.2, allowing administrators to input JavaScript through the Home Page editor, which could potentially lead to stored cross-site scripting (XSS) issues. However, the actual risk is considered low due to the administrative privileges that allow for template modifications and plugin installations, which can mitigate the impact. Organizations using this version of Grav should prioritize monitoring and securing their admin interfaces to prevent misuse of this capability.

CVE
CVE-2025-64059
Severity
LOW
CVSS
1.8
EPSS
0.23%
Java

Original NVD Description

Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.