Cross-site scripting in Grav CMS - CVE-2025-66308
Published: May 5, 2026
Grav CMS
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a user's browser.
The vulnerability exists due to cross-site scripting in the /admin/config/site endpoint parameter data[taxonomies] when processing crafted site configuration input. A remote privileged user can submit a specially crafted POST request to execute arbitrary script in a user's browser.
User interaction is required for a user to access the affected configuration or related administrative interface where the stored payload is rendered.