SSRF Vulnerability in Grav by Get Grav
CVE-2025-66844
9.1CRITICAL
What is CVE-2025-66844?
A vulnerability exists in Grav versions earlier than 1.7.49.5 that may be exploited through a Server-Side Request Forgery (SSRF) vector. This issue arises when page content is processed through Twig templates, allowing an attacker to trigger unauthorized requests if the configuration permits the registration of undefined PHP functions. This can potentially expose the server to further attacks or sensitive data leakage.
