Vendor Review Manipulation in Vvveb CMS by Low-Privileged Users
CVE-2026-49223

7.6HIGH

Key Information:

Vendor

Givanz

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-49223?

In Vvveb CMS versions prior to 1.0.8.4, a vulnerability exists in the backend review operations that allows a low-privileged vendor to manipulate reviews associated with another vendor's products. The system inadvertently accepts a user-controlled 'product_review_id' without proper validation against the associated 'product.admin_id' for the current admin user. This oversight permits attackers to view sensitive review content, ratings, and author information, as well as modify review statuses and delete reviews. Consequently, this not only compromises the visibility and integrity of product reviews but also poses significant risks to the credibility of the review process within the platform. This issue has been addressed in version 1.0.8.4.

Affected Version(s)

Vvveb < 1.0.8.4

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.