CVE-2025-64059

Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.

  • Published Sep 13, 2026
  • CVSS 1.8 low
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2025-64059 at the National Vulnerability Database