Vvveb · Vvveb · CVE-2026-54506
**Name of the Vulnerable Software and Affected Versions**
Vvveb versions prior to 1.0.8.5
**Description**
A flaw exists in the way user profile bios are processed. The file 'app/controller/user/profile.php' accepts the `user[bio]` field and processes it using the `sanitizeHTML()` function in 'system/functions.php'. Due to a regular expression error regarding the forward-slash delimiter and a faulty do-while condition, forbidden nested tags are only removed once. This allows users with an Author role or higher to bypass sanitization by submitting nested forbidden tags or solidus-prefixed event-handler markup. The unsanitized content is rendered without sufficient output encoding on the '/author/{username}' endpoint, in the admin user-management view, and potentially in comment displays. This can lead to the execution of attacker-controlled JavaScript, potentially exposing browser-session data, enabling account actions in the victim's context, defacement, or phishing.
**Recommendations**
Update to version 1.0.8.5.