Security Advisory

CVE-2025-66844

9.1
CRITICAL

Vulnerability Description

In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered
Published Date December 15, 2025
Official Source NIST NVD Advisory