Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

M1N9Yu3

#31716of 57,427
8.8Total CVSS
Vulnerabilities · 1
PT-2026-95144
8.8
2026-09-17
Vvveb · Vvveb · CVE-2026-54612
**Name of the Vulnerable Software and Affected Versions** Vvveb versions 1.0.0 through 1.0.8.4 **Description** An authenticated user with the Editor role and `editor/*` permission can perform a path traversal attack. The `saveGlobalElements()` function in `admin/controller/editor/global-trait.php` improperly concatenates the `data-v-save-global` variable to the active theme directory before it is processed by `loadHTMLFile()` and `file put contents()`. By submitting crafted HTML to the `module=editor/editor&action=save` endpoint, an attacker can write PHP content to a writable file outside the theme directory. If the target file is web-accessible, such as using the `public/vadmin/index.php` entrypoint as a trampoline, it allows for remote code execution and the placement of a persistent webshell, compromising the confidentiality, integrity, and availability of the application. **Recommendations** Update Vvveb to version 1.0.8.5.