Vvveb CMS Vulnerability Allows Unauthorized Question Management
CVE-2026-49222
7.6HIGH
What is CVE-2026-49222?
A vulnerability in Vvveb CMS allows low-privileged Vendors to manage product questions of other Vendors, posing a risk to data integrity and confidentiality. The backend operations do not adequately restrict access based on admin IDs, enabling unauthorized users to read and manipulate question content, change statuses, and even delete entries. This flaw can compromise the integrity of product Q&A sections, negatively affecting user trust and operational security. An update has been released in version 1.0.8.4 to address this issue.
Affected Version(s)
Vvveb < 1.0.8.4
