---
id: CVE-2025-64059
title: Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor
summary: >-
  Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor.
  NOTE: the relevance of this for stored XSS is disputed because admins are
  allowed to modify templates, install plugins, and upload other executable
  content.
severity: low
cvss: 1.8
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
vendor: getgrav
product: Grav
affected:
  - Grav 1.7.50.2
published: '2026-09-13'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T13:42:45.910'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64059'
references:
  - url: >-
      https://drive.google.com/file/d/1gbzdiaZEGTPwUPKLengVRO2Nijc6OVuy/view?usp=sharing
    label: cve@mitre.org
  - url: >-
      https://drive.google.com/file/d/1gbzdiaZEGTPwUPKLengVRO2Nijc6OVuy/view?usp=sharing
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00299
epssPercentile: 0.20074
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T18:19:16.767848Z'
ingestedAt: '2026-09-14T15:23:07.469Z'
---

## Overview

Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
