{"id":"CVE-2025-66310","aliases":["GHSA-7g78-5g5g-mvfj"],"url":"https://o3.security/vulnerability/CVE-2025-66310","summary":"Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` parameter `data[header][template]` in Advanced Tab","details":"This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/[page] endpoint of the Grav application. This vulnerability allows attackers to inject malicious scripts into the data[header][template] parameter. The script is saved within the page's frontmatter and executed automatically whenever the affected content is rendered in the administrative interface or frontend view. This vulnerability is fixed in 1.11.0-beta.1.","published":"2025-12-01T22:04:09.187Z","modified":"2026-08-08T03:48:16.132183791Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"getgrav/grav","fixedVersion":"1.8.0-beta.27"}],"fix":{"url":"https://github.com/getgrav/grav-plugin-admin/commit/99f653296504f1d6408510dd2f6f20a45a26f9b0","label":"getgrav/grav-plugin-admin@99f6532"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66310.json"},{"type":"ADVISORY","url":"https://github.com/getgrav/grav/security/advisories/GHSA-7g78-5g5g-mvfj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66310"},{"type":"FIX","url":"https://github.com/getgrav/grav-plugin-admin/commit/99f653296504f1d6408510dd2f6f20a45a26f9b0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:16.132183791Z"}}