PT-2026-95144 · Vvveb · Vvveb

·

CVE-2026-54612

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vvveb versions 1.0.0 through 1.0.8.4
Description An authenticated user with the Editor role and editor/* permission can perform a path traversal attack. The saveGlobalElements() function in admin/controller/editor/global-trait.php improperly concatenates the data-v-save-global variable to the active theme directory before it is processed by loadHTMLFile() and file put contents(). By submitting crafted HTML to the module=editor/editor&action=save endpoint, an attacker can write PHP content to a writable file outside the theme directory. If the target file is web-accessible, such as using the public/vadmin/index.php entrypoint as a trampoline, it allows for remote code execution and the placement of a persistent webshell, compromising the confidentiality, integrity, and availability of the application.
Recommendations Update Vvveb to version 1.0.8.5.

Exploit

Fix

Code Injection

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54612
GHSA-C3V9-3XRQ-PVQV

Affected Products

Vvveb