Arbitrary File Write Vulnerability in Vvveb CMS
CVE-2026-54612

8.8HIGH

Key Information:

Vendor

Givanz

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54612?

The Vvveb CMS versions from 1.0.0 to 1.0.8.5 contains a vulnerability in the saveGlobalElements() function, allowing an authenticated user with Editor permissions to craft and submit malicious HTML, enabling file traversal to writable PHP files outside of the theme directory. This could lead to execution of unauthorized PHP code if the affected files are web-accessible, potentially compromising the confidentiality, integrity, and availability of the application. The vulnerability has been addressed and patched in version 1.0.8.5.

Affected Version(s)

Vvveb >= 1.0.0, < 1.0.8.5

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.