216.73.216.233

CVE-2025-66844

· Published 15/12/2025 16:15 · Modified 17/12/2025 15:38

Labels: CVE-2025-66844 2025-12-15CVE-2025-66844[email protected]

Essential information

Published
15/12/2025 16:15
Modified
17/12/2025 15:38
Author
Creator
CVSS
9.1 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CVSS metrics

Description

In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
getgrav / grav cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*

References