CVE-2025-66844: Getgrav Grav

Critical severity, CVSS 9.1. EPSS: 0.3% chance of exploitation in the next 30 days.

In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered

Affected products

  • Getgrav Grav: before 1.7.49.5 (fixed in 1.7.49.5)

Published 2025-12-15. Last modified 2026-06-17.