ZeroHour

CVE-2025-66844

PoC
CVSS 3.1
9.1 critical
EPSS
<1%p21
Published
()
Modified
Description

In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered

Vendors
getgrav
Products
grav
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.