{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-23T05:38:54.557","vulnerabilities":[{"cve":{"id":"CVE-2025-66304","sourceIdentifier":"security-advisories@github.com","published":"2025-12-01T22:15:50.080","lastModified":"2025-12-03T18:57:54.023","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section of the admin panel can view the password hashes of all users, including the admin user. This exposure can potentially lead to privilege escalation if an attacker can crack these password hashes. This vulnerability is fixed in 1.8.0-beta.27."}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L","baseScore":6.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":0.7,"impactScore":5.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"},{"lang":"en","value":"CWE-201"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*","versionStartIncluding":"1.7.46","versionEndExcluding":"1.8.0","matchCriteriaId":"A9B3FCDC-ADBD-4023-9AC7-154642622421"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta1:*:*:*:*:*:*","matchCriteriaId":"8A383F2E-C6BA-440B-B648-A3313B7D91C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta10:*:*:*:*:*:*","matchCriteriaId":"F7EF2DEC-2798-4D0D-9C27-0F01BAFEAEFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta11:*:*:*:*:*:*","matchCriteriaId":"530C6F64-F30B-4E93-9A12-D9625EA57483"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta12:*:*:*:*:*:*","matchCriteriaId":"9AC28BF9-626D-4514-91F0-F81DAB5D3602"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta13:*:*:*:*:*:*","matchCriteriaId":"307AA375-E531-4AE5-BA79-2F9D4DE7A05F"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta14:*:*:*:*:*:*","matchCriteriaId":"C2E3E312-485D-42B0-B465-64B6438CDCAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta15:*:*:*:*:*:*","matchCriteriaId":"5BE4B2F9-1B6D-4D18-916A-5C95A3213222"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta16:*:*:*:*:*:*","matchCriteriaId":"763207F0-92D1-4274-A30A-DE634C5852C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta17:*:*:*:*:*:*","matchCriteriaId":"1DE8F350-BA07-4DAA-AE4B-5E0A532B6828"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta18:*:*:*:*:*:*","matchCriteriaId":"F9150B94-0DF3-43F3-9806-39787A6C0E4D"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta19:*:*:*:*:*:*","matchCriteriaId":"BAA7C7EC-8FB2-445D-8A02-1743D87F5416"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta2:*:*:*:*:*:*","matchCriteriaId":"7A6BEA2A-D534-4C9E-811A-8A46E214C46D"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta20:*:*:*:*:*:*","matchCriteriaId":"7A644F57-FF39-4262-9796-7C4F3B0851C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta21:*:*:*:*:*:*","matchCriteriaId":"B2AFB9E7-084E-497B-B0FC-CA6A5033C5BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta22:*:*:*:*:*:*","matchCriteriaId":"5C5E8823-9083-4FFA-9897-CAD0340DCE68"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta23:*:*:*:*:*:*","matchCriteriaId":"9C048938-E0EC-4AD0-9847-FD74E6770FE2"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta24:*:*:*:*:*:*","matchCriteriaId":"F7B43876-1445-418A-9707-E692FDF62C4D"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta25:*:*:*:*:*:*","matchCriteriaId":"94B209DE-01C6-41BA-B912-CF57849A9F7A"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta26:*:*:*:*:*:*","matchCriteriaId":"AB53AA10-87A5-4010-8019-BF4AA5ABC12B"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta3:*:*:*:*:*:*","matchCriteriaId":"775E0913-F3EF-4A55-B162-5BF9C6E2E641"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta4:*:*:*:*:*:*","matchCriteriaId":"3C3E022E-35CB-40AD-959A-F39949E38BD3"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta5:*:*:*:*:*:*","matchCriteriaId":"8779C813-A81A-4E21-AB86-6193933568BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta6:*:*:*:*:*:*","matchCriteriaId":"B608EDD4-207A-41A7-A60D-496FDA8EAFEA"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta7:*:*:*:*:*:*","matchCriteriaId":"AE1F2253-3EE0-4ADD-B8A5-C882A60FC626"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta8:*:*:*:*:*:*","matchCriteriaId":"81D4C859-5560-42F1-ACD9-65210E523F28"},{"vulnerable":true,"criteria":"cpe:2.3:a:getgrav:grav:1.8.0:beta9:*:*:*:*:*:*","matchCriteriaId":"156707A7-9507-4AC1-9CD0-90E32836E9DF"}]}]}],"references":[{"url":"https://github.com/getgrav/grav/commit/9d11094e4133f059688fad1e00dbe96fb6e3ead7","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/getgrav/grav/security/advisories/GHSA-gq3g-666w-7h85","source":"security-advisories@github.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://github.com/getgrav/grav/security/advisories/GHSA-gq3g-666w-7h85","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Vendor Advisory"]}]}}]}