Description
Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.
Published: 2026-09-13
Score: 1.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting via the Home Page editor
Action: Assess Impact
AI Analysis

Impact

Grav 1.7.50.2 permits an administrator to insert arbitrary Java a stored XSS flaw that can be exploited to execute client‑side scripts when end‑users view the affected page for script execution.

Affected Systems

The affected product is Grav CMS, specifically version 1.7.50.2. No other vendor or product versions are listed as affected in the current data.

Risk and Exploitability

The CVSS score of 1.8 indicates a low severity from a general perspective. The EPSS score of < 1% (0.00232) and the fact that the vulnerability is not listed in the CISA KEV catalog suggest a very modest probability of exploitation. However, the attack vector is local to administrators who have editing rights. If an attacker compromises an admin account or injects malicious code via the editor, the stored XSS could be leveraged to deface the site, steal session cookies from site visitors, or deliver phishing payloads. The risk is therefore low in isolated environments but can grow to high impact in high‑visibility or public websites.

Generated by OpenCVE AI on September 15, 2026 at 18:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Grav to a version that removes the editor JavaScript injection flaw, such as the next released patch after 1.7.50.2.
  • If an upgrade is not immediately feasible, configure the editor to strip or disallow script tags, or use a contentLimit access to the Home Page editor to trusted administrators only, and monitor editor activity for unexpected script insertion.
  • Validate that only authorized administrators have editing rights and regularly review the list of users with editor access.

Generated by OpenCVE AI on September 15, 2026 at 18:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title Stored XSS via Admin Home Page Editor in Grav CMS

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Stored XSS via JavaScript in Grav Home Page Editor
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Title Stored XSS via JavaScript in Grav Home Page Editor

Sun, 13 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.
First Time appeared Getgrav
Getgrav grav
Weaknesses CWE-79
CPEs cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*
Vendors & Products Getgrav
Getgrav grav
References
Metrics cvssV3_1

{'score': 1.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T18:19:51.712Z

Reserved: 2025-10-27T00:00:00.000Z

Link: CVE-2025-64059

cve-icon Vulnrichment

Updated: 2026-09-14T18:19:47.211Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T19:16:52.707

Modified: 2026-09-16T13:42:45.910

Link: CVE-2025-64059

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:30:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')