CVE-2025-66303Medium· 4.9▾ SunlitGrav is a file-based Web platform. Prior to 1.8.0-beta.27, A Denial of Service (DoS) vulnerability has been identified in Grav related to the handling of scheduled_at parameters. Specifically, the application fails to properly sanitize i…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A Denial of Service (DoS) vulnerability has been identified in Grav related to the handling of scheduled_at parameters. Specifically, the application fails to properly sanitize input for cron expressions. By manipulating the scheduled_at parameter with a malicious input, such as a single quote, the application admin panel becomes non-functional, causing significant disruptions to administrative operations. The only way to recover from this issue is to manually access the host server and modify the backup.yaml file to correct the corrupted cron expression. This vulnerability is fixed in 1.8.0-beta.27.
grav < 1.8.0grav = 1.8.0Upgrade past the affected range:
grav 1.8.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-66304Medium· 6.2Grav is a file-based Web platform
CVE-2025-66306Medium· 4.3Grav is a file-based Web platform
CVE-2025-66299High· 8.8Grav is a file-based Web platform
CVE-2025-66300High· 8.5Grav is a file-based Web platform
CVE-2025-66301Critical· 9.6Grav is a file-based Web platform
CVE-2025-66302Medium· 6.8Grav is a file-based Web platform