Vvveb CMS Content Management System Vulnerability Allows Unauthorized Access to Products
CVE-2026-49228

8.8HIGH

Key Information:

Vendor

Givanz

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-49228?

Vvveb CMS, a versatile content management system, is susceptible to a vulnerability that allows vendors with low privileges to potentially access and manipulate products belonging to other vendors. This issue arises because the backend operations do not consistently apply the current admin ID when executing certain actions related to product duplication or deletion. As a result, an attacker could exploit this flaw to read sensitive product information, duplicate items, or inadvertently delete critical catalog data. The risk of unauthorized access could lead to data loss, commercial information exposure, and significant disruptions to business operations. This vulnerability has been addressed in version 1.0.8.4.

Affected Version(s)

Vvveb < 1.0.8.4

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.