Directory Traversal Vulnerability in Vvveb CMS
CVE-2026-54613

5.4MEDIUM

Key Information:

Vendor

Givanz

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54613?

A directory traversal vulnerability exists in Vvveb CMS versions prior to 1.0.8.5, where the getThemeFolder() function fails to properly sanitize user input, allowing authenticated users with Editor permissions to manipulate paths. This can lead to unauthorized access to sensitive .html backup files located outside the web root. Attackers can exploit this issue to either read sensitive exported site content or delete backup data, provided they have a valid admin session and the necessary CSRF token.

Affected Version(s)

Vvveb < 1.0.8.5

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.