Vulnerabilities & PatchesEmerging1 src
CVE-2025-64059 - Grav Stored Cross-Site Scripting
CVE ID : CVE-2025-64059
Published : Sept. 13, 2026, 7:16 p. m.
• 1 hour, 36 minutes ago
Description : Grav 1. 7. 50. 2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.
Severity: 1.8
• LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...