PT-2026-95145 · Vvveb · Vvveb

·

CVE-2026-54613

·

Published

2026-09-17

·

Updated

2026-09-22

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Vvveb versions prior to 1.0.8.5
Description An issue exists where the getThemeFolder() function in admin/controller/editor/revisions.php returns the theme parameter without proper sanitization. The backupFolder() function then concatenates this parameter beneath DIR THEMES before the editor/revisions/load or editor/revisions/delete endpoints operate on a .html file. While sanitizeBackupFileName() removes traversal characters from the file parameter, it fails to protect the theme directory component. An authenticated user with the Editor role and editor/* permission can use traversal sequences to redirect file get contents() or unlink() to backup subdirectories outside the web root. This requires a valid admin session and CSRF token. The impact includes the disclosure of sensitive exported site content (limited to .html files in backup directories) or the removal of backup data, provided the system has filesystem write permissions.
Recommendations Update to version 1.0.8.5.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54613
GHSA-GJXP-VRCW-69V8

Affected Products

Vvveb