Stored Cross-Site Scripting Vulnerability in Vvveb CMS by Givanz
CVE-2026-44366

6.1MEDIUM

Key Information:

Vendor

Givanz

Status
Vendor
CVE Published:
15 May 2026

What is CVE-2026-44366?

Vvveb CMS, a flexible content management system with a built-in page builder, previously had a vulnerability in its comment submission process. This flaw allowed unauthenticated users to submit malicious scripts through the author field in comment submissions, which were then stored without proper sanitization. The unsanitized content could later be rendered on public post pages, exposing visitors to potentially harmful scripts. This vulnerability has been addressed and fixed in version 1.0.8.1.

Affected Version(s)

Vvveb < 1.0.8.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.