ZeroHour

CVE-2025-46198

PoC ×2
CVSS 3.1
8.8 high
EPSS
<1%p48
Published
()
Modified
Description

Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code via the onerror attribute of the img element

Vendors
getgrav
Products
grav
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.