CVE-2025-46198: XSS
Published Jul 25, 2025
·Updated
Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code via the onerror attribute of the img element
Affected Software
2 affected components
Grav Grav>=1.7.46<=1.7.48
getgrav grav>=1.7.46<=1.7.48
Event History
Jul 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-46198?
CVE-2025-46198 has a critical severity rating due to its ability to allow arbitrary code execution.
2
How do I fix CVE-2025-46198?
To fix CVE-2025-46198, upgrade Grav to version 1.7.49 or later.
3
What versions of Grav are affected by CVE-2025-46198?
CVE-2025-46198 affects Grav versions 1.7.46, 1.7.47, and 1.7.48.
4
What type of vulnerability is CVE-2025-46198?
CVE-2025-46198 is a Cross Site Scripting (XSS) vulnerability.
5
What can an attacker achieve with CVE-2025-46198?
An attacker can execute arbitrary code in the context of a victim's browser using the onerror attribute of the img element.