Skip to content

Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` parameter `data[header][template]` in Advanced Tab

Moderate severity GitHub Reviewed Published Dec 1, 2025 in getgrav/grav

No open alerts for this advisory

Give feedback on Dependabot alerts