CVE-2025-66843: XSS
grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An authenticated low-privileged user with permission to edit content can inject malicious JavaScript payloads into editable fields. The payload is stored on the server and later executed when any other user views or edits the affected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66843?
The severity of CVE-2025-66843 is classified as medium due to its potential for exploitation through stored cross-site scripting.
Who is affected by CVE-2025-66843?
CVE-2025-66843 affects users of Grav versions prior to 1.7.49.5 that allow authenticated low-privileged users to edit content.
How do I fix CVE-2025-66843?
To fix CVE-2025-66843, upgrade Grav to version 1.7.49.5 or later.
What type of vulnerability is CVE-2025-66843?
CVE-2025-66843 is a Stored Cross-Site Scripting (Stored XSS) vulnerability.
What impact does CVE-2025-66843 have on users?
CVE-2025-66843 allows attackers to inject malicious JavaScript into editable fields, which can later be executed when the content is viewed.