Impact
Grav 1.7.50.2 permits an administrator to insert arbitrary Java a stored XSS flaw that can be exploited to execute client‑side scripts when end‑users view the affected page for script execution.
Affected Systems
The affected product is Grav CMS, specifically version 1.7.50.2. No other vendor or product versions are listed as affected in the current data.
Risk and Exploitability
The CVSS score of 1.8 indicates a low severity from a general perspective. The EPSS score of < 1% (0.00232) and the fact that the vulnerability is not listed in the CISA KEV catalog suggest a very modest probability of exploitation. However, the attack vector is local to administrators who have editing rights. If an attacker compromises an admin account or injects malicious code via the editor, the stored XSS could be leveraged to deface the site, steal session cookies from site visitors, or deliver phishing payloads. The risk is therefore low in isolated environments but can grow to high impact in high‑visibility or public websites.
OpenCVE Enrichment