Vvveb 是一个功能强大且易于使用的 CMS,内置页面构建器,可用于构建网站、博客或电子商务商店。在 1.0.8.5 版本之前,app/controller/user/profile.php 文件接受 user[bio] 字段输入,并通过 system/functions.php 中的 sanitizeHTML() 函数对存储的内容进行清理。然而,该函数中用于处理 on* 事件处理器的正则表达式遗漏了正斜杠(/)分隔符,且其 do-while 循环的条件是将字符串与其自身进行比较,导致被禁止的嵌套标签仅被移除一次
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54612 | 8.8 HIGH | Vvveb: Authenticated editor path traversal to PHP file write/RCE via data-v-save-global |
| CVE-2026-54507 | 8.4 HIGH | Vvveb oEmbedProxy vulnerable to server-side request forgery |
| CVE-2026-54613 | 5.4 MEDIUM | Vvveb: Path Traversal in Revision Backup Reader/Deleter via Unsanitized theme Parameter |
No comments yet