Cross-site scripting in Grav CMS - CVE-2025-66311
Published: May 5, 2026
Grav CMS
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a user's browser.
The vulnerability exists due to cross-site scripting in the /admin/pages/[page] endpoint when processing page metadata and taxonomy parameters. A remote privileged user can submit a specially crafted POST request containing malicious script in data[header][metadata], data[header][taxonomy][category], or data[header][taxonomy][tag] to execute arbitrary script in a user's browser.
User interaction is required when the affected page is accessed or rendered in the administrative interface.