CVE-2025-46199: XSS
Published Jul 25, 2025
·Updated
Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafted script to the form fields
Affected Software
2 affected components
Grav Grav<1.7.48
getgrav grav<=1.7.48
Event History
Jul 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-46199?
CVE-2025-46199 is classified as a high-severity Cross Site Scripting vulnerability.
2
How do I fix CVE-2025-46199?
To fix CVE-2025-46199, upgrade to Grav version 1.7.49 or later.
3
What versions of Grav are affected by CVE-2025-46199?
CVE-2025-46199 affects Grav versions up to and including 1.7.48.
4
What are the potential impacts of CVE-2025-46199?
Exploitation of CVE-2025-46199 could allow attackers to execute arbitrary scripts in users' browsers.
5
Is user data at risk due to CVE-2025-46199?
Yes, CVE-2025-46199 may expose user data by allowing attackers to execute malicious scripts.