CVE-2025-64059
Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.
- Published Sep 13, 2026
- CVSS 1.8 low
- 0.3% chance of exploitation in the next 30 days (EPSS)