Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. getgrav/grav
  4. ›
  5. CVE-2025-65186

CVE-2025-65186: Grav CMS is vulnerable to Cross Site Scripting (XSS) in the page editor

December 2, 2025 (updated December 3, 2025)

Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page content via a Markdown editor. The editor fails to properly sanitize tags, allowing stored XSS payloads to execute when pages are viewed in the admin interface.

References

  • github.com/advisories/GHSA-cchq-397m-q2qm
  • github.com/getgrav/grav
  • github.com/lukehebe/Vulnerability-Disclosures/blob/main/CVE-2025-65186.pdf
  • nvd.nist.gov/vuln/detail/CVE-2025-65186

Code Behaviors & Features

Detect and mitigate CVE-2025-65186 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 1.7.49

Solution

Unfortunately, there is no solution available yet.

Impact 6.1 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

packagist/getgrav/grav/CVE-2025-65186.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sun, 14 Dec 2025 00:19:08 +0000.