Vulnerability Description
Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://drive.google.com/file/d/1gbzdiaZEGTPwUPKLengVRO2Nijc6OVuy/view?usp=shari
- https://drive.google.com/file/d/1gbzdiaZEGTPwUPKLengVRO2Nijc6OVuy/view?usp=shari
FAQ
What is CVE-2025-64059?
CVE-2025-64059 is a vulnerability with a CVSS score of 1.8 (LOW). Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and up...
How severe is CVE-2025-64059?
CVE-2025-64059 has been rated LOW with a CVSS base score of 1.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-64059?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.