← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 13, 2026 · 19:16via CVEFeed

CVE-2025-64059 - Grav Stored Cross-Site Scripting

Brief

CVE ID : CVE-2025-64059

Published : Sept. 13, 2026, 7:16 p. m.

  • 1 hour, 36 minutes ago

Description : Grav 1.

  • 50. 2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.

Severity: 1.8

  • LOW

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed→