CVE-2025-64059: Getgrav Grav
Low severity, CVSS 1.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.
Affected products
- Getgrav Grav: version 1.7.50.2 only
Published 2026-09-13. Last modified 2026-09-16.