Reflected Cross-Site Scripting Vulnerability in Grav Admin Plugin
CVE-2025-66309
6.2MEDIUM
What is CVE-2025-66309?
The Grav Admin Plugin, which provides an HTML user interface for configuring and managing the Grav application, has a Reflected Cross-Site Scripting (XSS) vulnerability in the /admin/pages/[page] endpoint. This vulnerability can be exploited by attackers to inject malicious scripts through the data[header][content][items] parameter, potentially compromising the security of affected setups. The issue has been resolved in versions 1.11.0-beta.1 and later, emphasizing the necessity for users to update their installations promptly.
Affected Version(s)
grav < 1.11.0-beta.1
