Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-65186

Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page content via a Markdown editor. The editor fails to properly sanitize <script> tags, allowing stored XSS payloads to execute when pages are viewed in the admin interface.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 7.4%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2025-65186
  • Getgrav » Grav » Version: 1.7.49
    cpe:2.3:a:getgrav:grav:1.7.49


Contact Us

Shodan ® - All rights reserved