CVE-2025-64059: Getgrav Grav

Low severity, CVSS 1.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.

Affected products

  • Getgrav Grav: version 1.7.50.2 only

Published 2026-09-13. Last modified 2026-09-16.