Directory Traversal Vulnerability in Vvveb CMS
CVE-2026-54613
5.4MEDIUM
What is CVE-2026-54613?
A directory traversal vulnerability exists in Vvveb CMS versions prior to 1.0.8.5, where the getThemeFolder() function fails to properly sanitize user input, allowing authenticated users with Editor permissions to manipulate paths. This can lead to unauthorized access to sensitive .html backup files located outside the web root. Attackers can exploit this issue to either read sensitive exported site content or delete backup data, provided they have a valid admin session and the necessary CSRF token.
Affected Version(s)
Vvveb < 1.0.8.5
