Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A Denial of Service (DoS) vulnerability has been identified in Grav related to the handling of scheduled_at parameters. Specifically, the application fails to properly sanitize input for cron expressions. By manipulating the scheduled_at parameter with a malicious input, such as a single quote, the application admin panel becomes non-functional, causing significant disruptions to administrative operations. The only way to recover from this issue is to manually access the host server and modify the backup.yaml file to correct the corrupted cron expression. This vulnerability is fixed in 1.8.0-beta.27.
History

Wed, 03 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta10:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta11:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta12:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta13:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta14:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta15:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta16:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta17:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta18:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta19:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta1:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta20:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta21:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta22:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta23:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta24:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta25:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta26:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta2:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta3:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta4:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta5:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta6:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta7:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta8:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:1.8.0:beta9:*:*:*:*:*:*

Wed, 03 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Dec 2025 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Getgrav
Getgrav grav
Vendors & Products Getgrav
Getgrav grav

Mon, 01 Dec 2025 21:45:00 +0000

Type Values Removed Values Added
Description Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A Denial of Service (DoS) vulnerability has been identified in Grav related to the handling of scheduled_at parameters. Specifically, the application fails to properly sanitize input for cron expressions. By manipulating the scheduled_at parameter with a malicious input, such as a single quote, the application admin panel becomes non-functional, causing significant disruptions to administrative operations. The only way to recover from this issue is to manually access the host server and modify the backup.yaml file to correct the corrupted cron expression. This vulnerability is fixed in 1.8.0-beta.27.
Title Grav is vulnerable to a DOS on the admin panel
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-12-01T21:35:47.423Z

Updated: 2025-12-03T15:10:31.896Z

Reserved: 2025-11-26T23:11:46.395Z

Link: CVE-2025-66303

cve-icon Vulnrichment

Updated: 2025-12-03T15:10:22.507Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-01T22:15:49.913

Modified: 2025-12-03T16:03:09.117

Link: CVE-2025-66303

cve-icon Redhat

No data.