Improper access control in Grav CMS - CVE-2025-66297
Published: May 5, 2026
Grav CMS
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in Twig processing in page rendering when rendering a page with attacker-controlled Twig expressions enabled in frontmatter. A remote user can inject malicious Twig expressions into editable page content to escalate privileges.
For privilege escalation, the same non-admin user must also be logged in to the site frontend when the crafted page is visited.