Improper access control in Grav CMS - CVE-2025-66301
Published: May 5, 2026
Grav CMS
Grav CMS
Description
The vulnerability allows a remote user to modify form processing actions.
The vulnerability exists due to improper access control in /admin/pages/{page_name} when handling crafted POST requests that modify data[_json][header][form]. A remote user can send a specially crafted request to modify form processing actions.
Exploitation requires the Admin and Form plugins to be installed.