Description
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, the oEmbedProxy() handler in admin/controller/editor/editor.php accepts an attacker-controlled url parameter and passes it to getUrl(), while validateUrl() in system/functions.php checks only the hostname string and does not validate its resolved addresses. An authenticated admin-panel user with editor/* permission can invoke GET /admin/index.php?module=editor/editor&action=oEmbedProxy with a dotted hostname or normalized loopback form that resolves to a private, loopback, link-local, or reserved address, causing the server to issue an HTTP or HTTPS request and return the response body. Storefront users and anonymous visitors cannot invoke the endpoint, but no CSRF token is required because the action uses GET. This can disclose internal service responses or cloud instance metadata and associated credentials. This issue is fixed in version 1.0.8.5.
Published: 2026-09-17
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure via SSRF
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows an authenticated admin with editor permission to trigger GET requests to arbitrary URLs through the oEmbedProxy endpoint. The request validation only checks hostname strings and does not resolve the IP address, enabling the server to fetch content from private, loopback, link‑local, or reserved addresses. This can expose internal service responses or cloud instance metadata that may contain credentials. The flaw results in high‑severity information disclosure rather than arbitrary code execution, but it is critical because it leaks data to anyone who has administrative access.

Affected Systems

Vvveb content management systems from givanz, versions earlier than 1.0.8.5, are affected. Any deployment running those versions, when accessed by an authenticated admin with editor privileges, can exploit the endpoint. Storefront users and anonymous visitors cannot invoke the endpoint because it lacks a CSRF token and requires admin authentication.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity level. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated admin exploiting the GET‑based oEmbedProxy action. Exploitation requires only normal admin credentials and an ability to construct a URL that resolves to a privileged address; no additional network access is required beyond the server’s outbound connections.

Generated by OpenCVE AI on September 19, 2026 at 00:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Vvveb to version 1.0.8.5 or later
  • Restrict editor privileges to only trusted accounts or remove the editor permission from non‑essential users
  • Configure firewall rules to block outbound connections from the web server to private, loopback, link‑local, or reserved IP ranges

Generated by OpenCVE AI on September 19, 2026 at 00:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Givanz
Givanz vvveb
Vendors & Products Givanz
Givanz vvveb

Thu, 17 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, the oEmbedProxy() handler in admin/controller/editor/editor.php accepts an attacker-controlled url parameter and passes it to getUrl(), while validateUrl() in system/functions.php checks only the hostname string and does not validate its resolved addresses. An authenticated admin-panel user with editor/* permission can invoke GET /admin/index.php?module=editor/editor&action=oEmbedProxy with a dotted hostname or normalized loopback form that resolves to a private, loopback, link-local, or reserved address, causing the server to issue an HTTP or HTTPS request and return the response body. Storefront users and anonymous visitors cannot invoke the endpoint, but no CSRF token is required because the action uses GET. This can disclose internal service responses or cloud instance metadata and associated credentials. This issue is fixed in version 1.0.8.5.
Title Vvveb oEmbedProxy vulnerable to server-side request forgery
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T14:43:10.025Z

Reserved: 2026-06-15T18:01:15.512Z

Link: CVE-2026-54507

cve-icon Vulnrichment

Updated: 2026-09-18T14:36:54.574Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:17:00.750

Modified: 2026-09-18T15:17:09.047

Link: CVE-2026-54507

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T00:15:13Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)