cvedb.io
CVE-2025-66306
MEDIUM · CVSS 4.3
EPSS exploitation probability: 0%
Published 2025-12-01T22:15:50.413 · Last modified 2026-06-17T09:56:38.983

Summary

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Panel which allows low-privilege users to access sensitive information from other accounts. Although direct account takeover is not possible, admin email addresses and other metadata can be exposed, increasing the risk of phishing, credential stuffing, and social engineering. This vulnerability is fixed in 1.8.0-beta.27.

Affected products

getgrav — grav

Does this affect you?

Add your gear to cvedb and we'll alert you only when getgrav ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.