CVE-2025-66844: Getgrav Grav
Critical severity, CVSS 9.1. EPSS: 0.3% chance of exploitation in the next 30 days.
In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered
Affected products
- Getgrav Grav: before 1.7.49.5 (fixed in 1.7.49.5)
Published 2025-12-15. Last modified 2026-06-17.