Логотип exploitDog
bind:CVE-2025-65186
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-65186

Количество 2

Количество 2

nvd логотип

CVE-2025-65186

2 месяца назад

Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page content via a Markdown editor. The editor fails to properly sanitize <script> tags, allowing stored XSS payloads to execute when pages are viewed in the admin interface.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-cchq-397m-q2qm

2 месяца назад

Grav CMS is vulnerable to Cross Site Scripting (XSS) in the page editor

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-65186

Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page content via a Markdown editor. The editor fails to properly sanitize <script> tags, allowing stored XSS payloads to execute when pages are viewed in the admin interface.

CVSS3: 6.1
0%
Низкий
2 месяца назад
github логотип
GHSA-cchq-397m-q2qm

Grav CMS is vulnerable to Cross Site Scripting (XSS) in the page editor

CVSS3: 6.1
0%
Низкий
2 месяца назад

Уязвимостей на страницу