Givan Vvveb是Givan个人开发者的一款网站内容管理与组件构建系统。 Givan Vvveb 1.0.8.4之前版本存在授权问题漏洞,该漏洞源于产品评论操作未验证评论所属产品与当前管理员的所有权关系,可能导致低权限供应商读取、修改或删除其他供应商产品下的评论内容,操纵产品评论可见性和完整性。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-49221 | 8.8 HIGH | Vvveb digital asset authorization bypass allows Vendors to list, read, edit, or delete oth |
| CVE-2026-49228 | 8.8 HIGH | Vvveb product authorization bypass allows Vendors to read, duplicate, or delete other Vend |
| CVE-2026-49225 | 8.3 HIGH | Vvveb product revision authorization bypass allows Vendors to read, restore, or delete oth |
| CVE-2026-49226 | 8.3 HIGH | Vvveb post authorization bypass allows Authors to view, duplicate, or delete other Authors |
| CVE-2026-49224 | 8.3 HIGH | Vvveb post revision authorization bypass allows Authors to read, restore, or delete other |
| CVE-2026-49227 | 7.6 HIGH | Vvveb comment authorization bypass allows Authors to read, approve, edit, or delete commen |
| CVE-2026-49222 | 7.6 HIGH | Vvveb product question authorization bypass allows Vendors to read, approve, edit, or dele |
No comments yet