CVE-2025-66844 - Grav SSRF Vulnerability
CVE ID : CVE-2025-66844
Published : Dec. 15, 2025, 4:15 p.m. | 1 hour, 44 minutes ago
Description : In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Dec. 15, 2025, 4:15 p.m. | 1 hour, 44 minutes ago
Description : In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...