Grav CMS is vulnerable to Cross Site Scripting (XSS) in the page editor
Moderate severity
GitHub Reviewed
Published
Dec 2, 2025
to the GitHub Advisory Database
•
Updated Dec 3, 2025
Description
Published by the National Vulnerability Database
Dec 2, 2025
Published to the GitHub Advisory Database
Dec 2, 2025
Last updated
Dec 3, 2025
Reviewed
Dec 3, 2025
Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page content via a Markdown editor. The editor fails to properly sanitize <script> tags, allowing stored XSS payloads to execute when pages are viewed in the admin interface.
References