Vvveb 是一款功能强大且易于使用的 CMS,内置页面构建器,可用于构建网站、博客或电子商务商店。在 1.0.8.5 之前, 中的 直接返回攻击者可控的 参数,未进行任何净化处理;随后 将其拼接在 之后,而 或 会在指定 文件上执行操作。 仅对独立的 参数中的路径遍历字符进行过滤,却未对 目录组件提供保护。 拥有默认 Editor 角色并具备 权限的已认证用户可提交路径遍历序列,使 或 指向 Web 根目录之外可访问的备份子目录。该漏洞利用需要一个有效的管理员会话和 CSRF 令牌;读取操作仅限于备份目录中的 文
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54612 | 8.8 HIGH | Vvveb: Authenticated editor path traversal to PHP file write/RCE via data-v-save-global |
| CVE-2026-54507 | 8.4 HIGH | Vvveb oEmbedProxy vulnerable to server-side request forgery |
| CVE-2026-54506 | 7.6 HIGH | Vvveb: Stored XSS via sanitizeHTML() bypass in user profile bio field |
No comments yet