Junglewise Threat Intelligence

CVE-2025-64059: Grav stored cross-site scripting in Home Page editor

CVE-2025-64059 · Severity: low · CVSS 1.8 · Published 2026-09-13

Technologies: Grav. Vendors: Grav.

Executive brief

Grav, a flat-file content management system, allows site administrators to inject malicious JavaScript code through the Home Page editor. While this vulnerability requires administrative privileges to exploit, it represents a stored XSS risk if an admin account is compromised or misused, potentially allowing an attacker to execute arbitrary code in the browsers of site visitors.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in Grav's Home Page editor that permits injection of JavaScript code. The attack requires administrative privileges to access the editor. The injected script is stored and executed in the browsers of visitors viewing the home page. The relevance as a true XSS vulnerability is disputed within the security community because administrators already have broad permissions to modify templates, install plugins, and upload executable content—meaning this does not expand the threat model significantly beyond existing admin capabilities. Patches or configuration restrictions may be available; refer to vendor documentation.

Affected products

  • Grav Grav 1.7.50.2

Timeline

  • 2026-09-13: disclosed

References

Related threats