Vvveb 是一款功能强大且易于使用的 CMS,内置页面构建器,可用于构建网站、博客或电子商务商店。在 1.0.8.5 之前的版本中,admin/controller/editor/editor.php 文件中的 oEmbedProxy() 处理函数接受由攻击者控制的 url 参数,并将其传递给 getUrl() 函数;同时,system/functions.php 中的 validateUrl() 函数仅检查主机名字符串,而不验证其解析后的 IP 地址。因此,拥有 editor/* 权限的已认证后台管理用户可以通
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54612 | 8.8 HIGH | Vvveb: Authenticated editor path traversal to PHP file write/RCE via data-v-save-global |
| CVE-2026-54506 | 7.6 HIGH | Vvveb: Stored XSS via sanitizeHTML() bypass in user profile bio field |
| CVE-2026-54613 | 5.4 MEDIUM | Vvveb: Path Traversal in Revision Backup Reader/Deleter via Unsanitized theme Parameter |
No comments yet