Vvveb CMS Content Management System Vulnerability Allows Unauthorized Access to Products
CVE-2026-49228
8.8HIGH
What is CVE-2026-49228?
Vvveb CMS, a versatile content management system, is susceptible to a vulnerability that allows vendors with low privileges to potentially access and manipulate products belonging to other vendors. This issue arises because the backend operations do not consistently apply the current admin ID when executing certain actions related to product duplication or deletion. As a result, an attacker could exploit this flaw to read sensitive product information, duplicate items, or inadvertently delete critical catalog data. The risk of unauthorized access could lead to data loss, commercial information exposure, and significant disruptions to business operations. This vulnerability has been addressed in version 1.0.8.4.
Affected Version(s)
Vvveb < 1.0.8.4
