CVE-2025-66298: Getgrav Grav
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav configuration details (including plugin configuration details) by using the correct POST payload to exploit a Server-Side Template (SST) vulnerability. Sensitive information may be contained in the configuration details. This vulnerability is fixed in 1.8.0-beta.27.
Affected products
- Getgrav Grav: before 1.8.0 (fixed in 1.8.0); version 1.8.0 only
Published 2025-12-01. Last modified 2026-09-26.