Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mh85-44c2-3m97 | Grav is vulnerable to Stored XSS through authenticated user-edited content |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://github.com/Yohane-Mashiro/grav_cve/issues/1 |
|
Thu, 18 Dec 2025 00:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:* |
Wed, 17 Dec 2025 07:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 17 Dec 2025 03:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Tue, 16 Dec 2025 06:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getgrav
Getgrav grav |
|
| Vendors & Products |
Getgrav
Getgrav grav |
Tue, 16 Dec 2025 01:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An authenticated low-privileged user with permission to edit content can inject malicious JavaScript payloads into editable fields. The payload is stored on the server and later executed when any other user views or edits the affected page. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-16T17:33:21.709Z
Reserved: 2025-12-08T00:00:00.000Z
Link: CVE-2025-66843
Updated: 2025-12-16T17:33:12.796Z
Status : Analyzed
Published: 2025-12-15T16:15:53.387
Modified: 2025-12-17T15:39:29.613
Link: CVE-2025-66843
No data.
OpenCVE Enrichment
Updated: 2025-12-16T06:33:36Z
Github GHSA