Vvveb CMS Vulnerability Allows Unauthorized Question Management
CVE-2026-49222

7.6HIGH

Key Information:

Vendor

Givanz

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-49222?

A vulnerability in Vvveb CMS allows low-privileged Vendors to manage product questions of other Vendors, posing a risk to data integrity and confidentiality. The backend operations do not adequately restrict access based on admin IDs, enabling unauthorized users to read and manipulate question content, change statuses, and even delete entries. This flaw can compromise the integrity of product Q&A sections, negatively affecting user trust and operational security. An update has been released in version 1.0.8.4 to address this issue.

Affected Version(s)

Vvveb < 1.0.8.4

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.