Remote Code Execution Vulnerability in Vvveb CMS by Givanz
CVE-2026-6249
8.7HIGH
What is CVE-2026-6249?
Vvveb CMS version 1.0.8 is susceptible to a remote code execution vulnerability due to an inadequate validation process in its media upload handler. Authenticated attackers can exploit this flaw by uploading a malicious PHP webshell with a .phtml extension to the publicly accessible media directory, effectively bypassing the configured deny-list for file extensions. Once the malicious file is uploaded, the attacker can invoke it through HTTP requests, leading to the potential compromise of the entire server. This vulnerability underscores the importance of rigorous input validation and secure file handling practices in web applications.
Affected Version(s)
Vvveb CMS 1.0.8
