Arbitrary File Access and Deletion in Vvveb CMS by Givanz
CVE-2026-55231
What is CVE-2026-55231?
Vvveb, a user-friendly content management system with an integrated page builder, is susceptible to a significant vulnerability that impacts users with higher access privileges. Before the release of version 1.0.8.6, the CMS featured an inadequate central path sanitization mechanism. This flaw allowed authenticated admin-panel users, particularly those with backup access, to read and delete arbitrary files on the server. Potential ramifications include unauthorized access to sensitive information such as database credentials stored in the config/db.php file, examination of critical system files like /etc/passwd, and the capability to delete essential configuration files, leading to a complete takeover by forcing the site into installation mode. Users are strongly encouraged to upgrade to the patched version to mitigate these risks.
Affected Version(s)
Vvveb < 1.0.8.6
