CVE-2025-66294High· 8.8▾ MidnightPoC availableGrav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor permissions to execute arbitrary commands on the server and, …
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 48.4 · likelihood 0.6 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.8%
Metasploit ×1 (last check)
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor permissions to execute arbitrary commands on the server and, under certain conditions, may also be exploited by unauthenticated attackers. This vulnerability stems from weak regex validation in the cleanDangerousTwig method. This vulnerability is fixed in 1.8.0-beta.27.
grav >= 1.7.48, < 1.8.0grav = 1.8.0Upgrade past the affected range:
grav 1.8.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-66299High· 8.8Grav is a file-based Web platform
CVE-2025-66297High· 8.8Grav is a file-based Web platform
CVE-2025-66298High· 7.5Grav is a file-based Web platform
CVE-2026-85604High· 8.8Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter
CVE-2025-66301Critical· 9.6Grav is a file-based Web platform
CVE-2026-92917High· 7.5Grav is a flat-file CMS