VYPR
Low severity1.8NVD Advisory· Published Sep 13, 2026

CVE-2025-64059

CVE-2025-64059

Description

Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.