Improper Neutralization of Special Elements Used in a Template Engine in Grav CMS - CVE-2025-66298
Published: May 5, 2026
Grav CMS
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to server-side template injection in the Forms plugin form handling when processing crafted POST form submissions. A remote attacker can send a specially crafted POST request to disclose sensitive information.
The issue can expose Grav configuration details, including plugin configuration details.