Resource exhaustion in Grav CMS - CVE-2025-66303
Published: May 5, 2026
Grav CMS
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper input validation in the admin panel scheduled_at parameter handling when processing crafted cron expression input. A remote privileged user can submit a specially crafted scheduled_at value to cause a denial of service.
The issue can render the admin panel non-functional, and recovery requires manual correction of the corrupted cron expression in the backup.yaml file.