Givan Vvveb是Givan个人开发者的一款网站内容管理与组件构建系统。 Givan Vvveb 1.0.8.4之前版本存在授权问题漏洞,该漏洞源于后端评论操作中接受调用者控制的comment_id,未验证comment.post_id与post.admin_id是否匹配,可能导致低权限作者管理其他作者文章下的评论,读取待审核评论内容和评论者邮箱,更改审核状态,编辑或删除评论。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-49221 | 8.8 HIGH | Vvveb digital asset authorization bypass allows Vendors to list, read, edit, or delete oth |
| CVE-2026-49228 | 8.8 HIGH | Vvveb product authorization bypass allows Vendors to read, duplicate, or delete other Vend |
| CVE-2026-49225 | 8.3 HIGH | Vvveb product revision authorization bypass allows Vendors to read, restore, or delete oth |
| CVE-2026-49226 | 8.3 HIGH | Vvveb post authorization bypass allows Authors to view, duplicate, or delete other Authors |
| CVE-2026-49224 | 8.3 HIGH | Vvveb post revision authorization bypass allows Authors to read, restore, or delete other |
| CVE-2026-49222 | 7.6 HIGH | Vvveb product question authorization bypass allows Vendors to read, approve, edit, or dele |
| CVE-2026-49223 | 7.6 HIGH | Vvveb product review authorization bypass allows Vendors to read, approve, edit, or delete |
No comments yet