Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, a flawed central path sanitizer lets an authenticated admin-panel user who holds backup access (default role site_admin or higher)
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55230 | 8.7 HIGH | Vvveb: Stored XSS in Vvveb via sanitizeHTML() filter bypass using a quoted greater-than ch |
| CVE-2026-55232 | 7.6 HIGH | Vvveb: Server-side request forgery in Vvveb via IPv6 bypass of validateUrl() in editor oEm |
No comments yet