Denial of Service Vulnerability in Grav Web Platform
CVE-2025-66305
6.9MEDIUM
What is CVE-2025-66305?
Grav, a file-based web platform, has a vulnerability in its admin configuration panel before version 1.8.0-beta.27. The vulnerability arises from improper user input validation in the 'Languages' submenu. When a malformed input, such as a single forward slash (/) or a cross-site scripting (XSS) test string, is entered, it can trigger a fatal regular expression parsing error on the server. This failure leads to an application-wide crash, rendering the site completely unavailable to all users. The issue has been resolved in version 1.8.0-beta.27, making it essential for users to update their installations.
Affected Version(s)
grav < 1.8.0-beta.27
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
