XML External Entity Injection Vulnerability in Vvveb by Givanz
CVE-2026-41936
8.6HIGH
What is CVE-2026-41936?
An XML external entity (XXE) injection vulnerability exists in Vvveb before version 1.0.8.2. This flaw is located in the admin Tools/Import feature, allowing an authenticated site administrator to read arbitrary files and potentially modify database records. Exploitation of this vulnerability can occur through the XML parser configuration in system/import/xml.php, enabling attackers to inject file:// or php://filter entity references. These references can lead to unauthorized file disclosure and the potential for overwriting administrator password hashes, leading to privilege escalation.
Affected Version(s)
Vvveb 0
