Grav CMS Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Grav CMS version 1.7.49.5. This issue allows remote attackers to inject arbitrary JavaScript, leading to stored XSS. The vulnerability arises because user input is returned without proper sanitization, enabling attackers to execute scripts in the context of the administrator's session.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.

Reproduction

To reproduce this vulnerability, upload a parameter that includes JavaScript. The injected script will be executed when the page is accessed, demonstrating the cross-site scripting flaw.

Added: Nov 3, 2025, 8:21 PM
Updated: Nov 3, 2025, 8:21 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
1.7
exploitability
7.9
remediation
7.7
relevance
0.8
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.