Modern, Crazy Fast, Ridiculously Easy and Amazingly Powerful Flat-File CMS
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2025-66298 getgrav/grav is vulnerable to Improper Neutralization of Special Elements Used in a Template Engine in versions 0.0.0 - 1.8.0-beta.27. | 0.0.0 - 1.8.0-beta.27 | High |
CVE-2025-66294 getgrav/grav is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 1.8.0-beta.27. | 0.0.0 - 1.8.0-beta.27 | High |
CVE-2025-66310 getgrav/grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.8.0-beta.27. | 0.0.0 - 1.8.0-beta.27 | Medium |
CVE-2025-66309 getgrav/grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.8.0-beta.27. | 0.0.0 - 1.8.0-beta.27 | Medium |
CVE-2025-66297 getgrav/grav is vulnerable to Improper Neutralization of Special Elements Used in a Template Engine in versions 0.0.0 - 1.8.0-beta.27. | 0.0.0 - 1.8.0-beta.27 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
twig/twig Version 3.x-dev | — | — |
filp/whoops Version ~2.16 | — | — |
nyholm/psr7 Version ^1.8 | — | — |
symfony/yaml Version ^6.4 || ^7.0 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant