Vvveb是Givan个人开发者的一个强大且易于使用的CMS,用于构建网站、博客或电子商务商店。 Vvveb 1.0.8.3之前版本存在安全漏洞,该漏洞源于管理员控制器调度周期中Base::init()在错误处理程序上重复调用permission(),导致无限递归耗尽PHP内存限制,可能导致攻击者从低权限账户发送持续请求到禁止的管理URL,耗尽所有工作进程的PHP内存,导致拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-41937 | 7.2 HIGH | Vvveb < 1.0.8.3 Unrestricted File Upload RCE via Plugin Upload |
| CVE-2026-41932 | 6.1 MEDIUM | Vvveb < 1.0.8.3 Stored XSS via Signup Controller |
| CVE-2026-41933 | 5.3 MEDIUM | Vvveb < 1.0.8.3 Directory Listing Information Disclosure |
No comments yet