PKSA-6ybw-qvkx-41s3 Security Advisory
-
[MEDIUM] Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` parameter `data[header][template]` in Advanced Tab
PKSA-6ybw-qvkx-41s3 CVE-2025-66310 GHSA-7g78-5g5g-mvfj
Affected package: getgrav/grav
Affected version: <1.8.0-beta.27
Reported by:
GitHub