CVE-2025-64059

LOW CVSS 3.1: 1.8 EPSS 0.23%
Updated Sep 16, 2026
Getgrav
Parameter Value
CVSS 1.8 (LOW)
Affected Versions 1.7.50.2 — 1.7.50.2
Type CWE-79 (Cross-Site Scripting (XSS))
Vendor Getgrav
Public PoC No

Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
High
Difficult to exploit
Privileges Required
High
Admin privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Getgrav Grav
cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*
1.7.50.2 <= 1.7.50.2