Denial of Service Vulnerability in Grav Web Platform
CVE-2025-66305

6.9MEDIUM

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
1 December 2025

What is CVE-2025-66305?

Grav, a file-based web platform, has a vulnerability in its admin configuration panel before version 1.8.0-beta.27. The vulnerability arises from improper user input validation in the 'Languages' submenu. When a malformed input, such as a single forward slash (/) or a cross-site scripting (XSS) test string, is entered, it can trigger a fatal regular expression parsing error on the server. This failure leads to an application-wide crash, rendering the site completely unavailable to all users. The issue has been resolved in version 1.8.0-beta.27, making it essential for users to update their installations.

Affected Version(s)

grav < 1.8.0-beta.27

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.