Denial of Service Vulnerability in Grav Web Platform
CVE-2025-66305
What is CVE-2025-66305?
Grav, a file-based web platform, has a vulnerability in its admin configuration panel before version 1.8.0-beta.27. The vulnerability arises from improper user input validation in the 'Languages' submenu. When a malformed input, such as a single forward slash (/) or a cross-site scripting (XSS) test string, is entered, it can trigger a fatal regular expression parsing error on the server. This failure leads to an application-wide crash, rendering the site completely unavailable to all users. The issue has been resolved in version 1.8.0-beta.27, making it essential for users to update their installations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
grav < 1.8.0-beta.27
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
