CVE-2025-64059 Details
Description
Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.
A stored cross-site scripting vulnerability has been identified in Grav version 1.7.50.2. This issue allows administrators to inject JavaScript through the Home Page editor. However, the significance of this vulnerability is debated, as administrators have the ability to modify templates, install plugins, and upload executable content.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 13, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://drive.google.com/file/d/1gbzdiaZEGTPwUPKLengVRO2Nijc6OVuy/view?usp=sharing | CISA-ADP | ExploitPartial Content |
| https://drive.google.com/file/d/1gbzdiaZEGTPwUPKLengVRO2Nijc6OVuy/view?usp=sharing | [email protected] | ExploitPartial Content |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Grav | 1.7.50.2 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | CISA-ADP |
| Sep 13, 2026 | New CVE Received | [email protected] |
Volerion