Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Josangeorge

#37066of 57,338
7.6Total CVSS
Vulnerabilities · 1
PT-2026-95141
7.6
2026-09-17
Vvveb · Vvveb · CVE-2026-54506
**Name of the Vulnerable Software and Affected Versions** Vvveb versions prior to 1.0.8.5 **Description** A flaw exists in the way user profile bios are processed. The file 'app/controller/user/profile.php' accepts the `user[bio]` field and processes it using the `sanitizeHTML()` function in 'system/functions.php'. Due to a regular expression error regarding the forward-slash delimiter and a faulty do-while condition, forbidden nested tags are only removed once. This allows users with an Author role or higher to bypass sanitization by submitting nested forbidden tags or solidus-prefixed event-handler markup. The unsanitized content is rendered without sufficient output encoding on the '/author/{username}' endpoint, in the admin user-management view, and potentially in comment displays. This can lead to the execution of attacker-controlled JavaScript, potentially exposing browser-session data, enabling account actions in the victim's context, defacement, or phishing. **Recommendations** Update to version 1.0.8.5.