CVE-2025-46198 Information

Description

Cross Site Scripting vulnerability in grav v.1.7.48 v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code via the onerror attribute of the img element

Reference

https://rapid-echo-f9c.notion.site/Grav-XSS-1dbaf8998a078072bb30ffc9b9e7ab4a?pvs=4 https://tyojong.tistory.com/1

CNNVD-202507-3128 (Published: 2025-07-25)

Share on: