CVE-2025-66306Medium· 4.3▾ SunlitGrav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Panel which allows low-privilege users to access sensitive information from other accounts…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Panel which allows low-privilege users to access sensitive information from other accounts. Although direct account takeover is not possible, admin email addresses and other metadata can be exposed, increasing the risk of phishing, credential stuffing, and social engineering. This vulnerability is fixed in 1.8.0-beta.27.
grav >= 1.7.48, < 1.8.0grav = 1.8.0Upgrade past the affected range:
grav 1.8.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-66303Medium· 4.9Grav is a file-based Web platform
CVE-2025-66304Medium· 6.2Grav is a file-based Web platform
CVE-2025-66299High· 8.8Grav is a file-based Web platform
CVE-2025-66300High· 8.5Grav is a file-based Web platform
CVE-2025-66301Critical· 9.6Grav is a file-based Web platform
CVE-2025-66302Medium· 6.8Grav is a file-based Web platform