Description
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, app/controller/user/profile.php accepts the user[bio] field and passes stored content through sanitizeHTML() in system/functions.php, whose on* event-handler regular expression omits the forward-slash delimiter and whose do-while condition compares the string to itself, so forbidden nested tags are removed only once. An Author-role or higher user can submit solidus-prefixed event-handler markup or nested forbidden tags that survive sanitization. The stored bio is rendered without sufficient output encoding on /author/{username}, in the admin user-management view, and potentially in comment displays, causing attacker-controlled JavaScript to execute when unauthenticated visitors, administrators, or other users view the content. This can expose browser-session data and permit victim-context account actions, defacement, or phishing. This issue is fixed in version 1.0.8.5.
Published: 2026-09-17
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting via stored bio injection
Action: Immediate Patch
AI Analysis

Impact

Vvveb CMS’s user profile bio field is used to store data that is later rendered on public, administrative, and comment pages. The application’s sanitizeHTML() function fails to strip solidus‑prefixed event‑handler attributes and nested forbidden tags, allowing attacker‑controlled JavaScript to persist in the bio. When unauthenticated visitors, administrators, or other users access a profile or view comments, the injected code executes in the victim’s browser. This flaw exposes the victim’s browser session, permits account‑taking actions within the same context, and enables defacement or phishing attacks.

Affected Systems

The vulnerability affects the Vvveb CMS from the vendor givanz. Any installation running a version earlier than 1.0.8.5 is susceptible. The fix is included in the 1.0.8.5 release and later.

Risk and Exploitability

The CVSS score of 7.6 indicates high severity, but the EPSS of less than 1% suggests a low likelihood of exploitation at present. The flaw is currently not listed in the CISA KEV catalog. Attackers would need to create or inject a malicious bio as a user with Author role or higher, and then rely on victims to view the affected profile or comment page, which can be achieved automatically via contextual link clicks. The impact is thus confined to browsers rendering the content, with potential for session hijacking and malicious page interaction.

Generated by OpenCVE AI on September 19, 2026 at 01:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the CMS to version 1.0.8.5 or later to apply the vendor patch
  • If an upgrade cannot be performed immediately, disable or remove the bio field from user profiles or enforce whitelisting that strips event‑handler attributes
  • Ensure that all profile and comment outputs use proper HTML escaping before rendering to prevent script execution

Generated by OpenCVE AI on September 19, 2026 at 01:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Givanz
Givanz vvveb
Vendors & Products Givanz
Givanz vvveb

Thu, 17 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, app/controller/user/profile.php accepts the user[bio] field and passes stored content through sanitizeHTML() in system/functions.php, whose on* event-handler regular expression omits the forward-slash delimiter and whose do-while condition compares the string to itself, so forbidden nested tags are removed only once. An Author-role or higher user can submit solidus-prefixed event-handler markup or nested forbidden tags that survive sanitization. The stored bio is rendered without sufficient output encoding on /author/{username}, in the admin user-management view, and potentially in comment displays, causing attacker-controlled JavaScript to execute when unauthenticated visitors, administrators, or other users view the content. This can expose browser-session data and permit victim-context account actions, defacement, or phishing. This issue is fixed in version 1.0.8.5.
Title Vvveb: Stored XSS via sanitizeHTML() bypass in user profile bio field
Weaknesses CWE-116
CWE-185
CWE-79
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-23T19:09:21.053Z

Reserved: 2026-06-15T18:01:15.512Z

Link: CVE-2026-54506

cve-icon Vulnrichment

Updated: 2026-09-23T19:09:01.023Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:17:00.537

Modified: 2026-09-23T20:17:11.123

Link: CVE-2026-54506

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:00:13Z

Weaknesses
  • CWE-116

    Improper Encoding or Escaping of Output

  • CWE-185

    Incorrect Regular Expression

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')