Vvveb 是一个强大且易于使用的 CMS(内容管理系统),内置页面构建器,可用于构建网站、博客或电子商务商店。 在 1.0.0 至 1.0.8.5 版本中, 文件中的 函数会在 和 操作之前,将攻击者可控的 参数中的文件名部分直接拼接(concatenate)到当前激活的主题目录下。 拥有默认 Editor 角色并具备 权限的已认证用户,可以向 提交特制的 HTML 数据,利用路径遍历(path traversal)机制,将文件写入主题目录之外的其他可写 PHP 文件位置。如果该目标路径对 Web 可访问,则编辑
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54507 | 8.4 HIGH | Vvveb oEmbedProxy vulnerable to server-side request forgery |
| CVE-2026-54506 | 7.6 HIGH | Vvveb: Stored XSS via sanitizeHTML() bypass in user profile bio field |
| CVE-2026-54613 | 5.4 MEDIUM | Vvveb: Path Traversal in Revision Backup Reader/Deleter via Unsanitized theme Parameter |
No comments yet