Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-54613— Vvveb: Path Traversal in Revision Backup Reader/Deleter via Unsanitized theme Parameter

Quick assessment

Affected
givanz Vvveb
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Vvveb 是一款功能强大且易于使用的 CMS,内置页面构建器,可用于构建网站、博客或电子商务商店。在 1.0.8.5 之前, 中的 直接返回攻击者可控的 参数,未进行任何净化处理;随后 将其拼接在 之后,而 或 会在指定 文件上执行操作。 仅对独立的 参数中的路径遍历字符进行过滤,却未对 目录组件提供保护。 拥有默认 Editor 角色并具备 权限的已认证用户可提交路径遍历序列,使 或 指向 Web 根目录之外可访问的备份子目录。该漏洞利用需要一个有效的管理员会话和 CSRF 令牌;读取操作仅限于备份目录中的 文

CVSS 5.4 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54613

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Vvveb: Path Traversal in Revision Backup Reader/Deleter via Unsanitized theme Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, getThemeFolder() in admin/controller/editor/revisions.php returns the attacker-controlled theme parameter without sanitization, and backupFolder() concatenates it beneath DIR_THEMES before editor/revisions/load or editor/revisions/delete operates on a named .html file. sanitizeBackupFileName() strips traversal characters only from the separate file parameter and does not protect the theme directory component. An authenticated user with the default Editor role and editor/* permission can submit traversal sequences that redirect file_get_contents() or unlink() to a reachable backup subdirectory outside the web root. A valid admin session and CSRF token are required, the read is limited to .html files in backup directories, and deletion additionally requires filesystem write permission. This can disclose sensitive exported site content or remove backup data. This issue is fixed in version 1.0.8.5.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
givanz Vvveb < 1.0.8.5 -

II. Public POCs for CVE-2026-54613

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54613

登录查看更多情报信息。

Patches & Fixes for CVE-2026-54613 (1)

Vendor Advisories for CVE-2026-54613 (1)

Vendor Pages for CVE-2026-54613 (1)

Same Patch Batch · givanz · 2026-09-17 · 4 CVEs total

CVE-2026-54612 8.8 HIGH Vvveb: Authenticated editor path traversal to PHP file write/RCE via data-v-save-global
CVE-2026-54507 8.4 HIGH Vvveb oEmbedProxy vulnerable to server-side request forgery
CVE-2026-54506 7.6 HIGH Vvveb: Stored XSS via sanitizeHTML() bypass in user profile bio field

IV. Related Vulnerabilities

V. Comments for CVE-2026-54613

No comments yet


Leave a comment