CVE-2025-66844
15.12.2025, 16:15
In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered
| Vendor | Product | Version |
|---|---|---|
| getgrav | grav | 𝑥 < 1.7.49.5 |
𝑥
= Vulnerable software versions