CVE-2025-65186
02.12.2025, 17:16
Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page content via a Markdown editor. The editor fails to properly sanitize <script> tags, allowing stored XSS payloads to execute when pages are viewed in the admin interface.
| Vendor | Product | Version |
|---|---|---|
| getgrav | grav | 1.7.49 |
𝑥
= Vulnerable software versions