Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gwfr-jfjf-92vv | Grav has Insecure Deserialization in File Cache |
Wed, 29 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Apr 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getgrav
Getgrav grav Cms |
|
| Vendors & Products |
Getgrav
Getgrav grav Cms |
Tue, 28 Apr 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file system/src/Grav/Framework/Cache/Adapter/FileCache.php of the component Cache Value Handler. The manipulation results in deserialization. The attack may be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made public and could be used. Upgrading to version 2.0.0-beta.2 addresses this issue. The patch is identified as c66dfeb5f. The affected component should be upgraded. | |
| Title | Grav CMS Cache Value FileCache.php doGet deserialization | |
| Weaknesses | CWE-20 CWE-502 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-29T13:01:56.731Z
Reserved: 2026-04-28T13:11:54.929Z
Link: CVE-2026-7317
Updated: 2026-04-29T12:59:12.110Z
Status : Deferred
Published: 2026-04-28T22:16:51.710
Modified: 2026-04-29T21:16:21.590
Link: CVE-2026-7317
No data.
OpenCVE Enrichment
Updated: 2026-04-29T10:10:24Z
Github GHSA