Description
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until 1.0.8.5, saveGlobalElements() in admin/controller/editor/global-trait.php concatenates the attacker-controlled file portion of data-v-save-global to the active theme directory before loadHTMLFile() and file_put_contents() operate on it. An authenticated user with the default Editor role and editor/* permission can submit crafted HTML to module=editor/editor&action=save and traverse to an existing writable PHP file outside the theme directory. If the target is web-accessible, editor-controlled PHP content executes in the web server context; a shipped public/vadmin/index.php entrypoint can be used as an execution trampoline rather than requiring a test-only file. This can permit persistent webshell placement and compromise application confidentiality, integrity, and availability. This issue is fixed in version 1.0.8.5.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from the saveGlobalElements method in Vvveb’s admin controller, which concatenates an attacker‑controlled file path from the data-v-save-global POST parameter to the active theme directory without proper sanitization. This allows an authenticated user with the default Editor role and editor/* permissions to submit crafted HTML that causes the server to write arbitrary PHP code into any writable file outside the theme directory, including publicly accessible files. The resulting PHP payload executes in the web server context, giving the attacker persistent shell access and the ability to compromise the application’s confidentiality, integrity, and availability.

Affected Systems

This flaw affects Vvveb CMS versions from 1.0.0 through 1.0.8.5 distributed by givanz. Users running those versions should verify they are running the latest patched release (1.0.8.5 or later) or otherwise restrict the Editor role’s write permissions.

Risk and Exploitability

The CVSS score of 8.8 reflects the high impact of remote code execution, whereas the EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers need authenticated access with Editor privileges and must submit a crafted request to module=editor/editor&action=save. Once the malicious content is written to a web‑accessible PHP file, it is executed immediately, enabling the attacker to maintain long‑term persistence on the host.

Generated by OpenCVE AI on September 19, 2026 at 01:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Vvveb to version 1.0.8.5 or later, which removes the vulnerable path handling logic.
  • Restrict the Editor role by removing editor/* permissions or limiting access to the editor action until a patch is applied.
  • Block execution of arbitrary files outside the intended webroot by tightening web‑server configuration, such as disabling PHP execution for modifiable directories or removing the public/vadmin/index.php entry point if not required.
  • Audit the filesystem for writable PHP files that may have been written by an attacker and remove or secure them.

Generated by OpenCVE AI on September 19, 2026 at 01:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Givanz
Givanz vvveb
Vendors & Products Givanz
Givanz vvveb

Thu, 17 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until 1.0.8.5, saveGlobalElements() in admin/controller/editor/global-trait.php concatenates the attacker-controlled file portion of data-v-save-global to the active theme directory before loadHTMLFile() and file_put_contents() operate on it. An authenticated user with the default Editor role and editor/* permission can submit crafted HTML to module=editor/editor&action=save and traverse to an existing writable PHP file outside the theme directory. If the target is web-accessible, editor-controlled PHP content executes in the web server context; a shipped public/vadmin/index.php entrypoint can be used as an execution trampoline rather than requiring a test-only file. This can permit persistent webshell placement and compromise application confidentiality, integrity, and availability. This issue is fixed in version 1.0.8.5.
Title Vvveb: Authenticated editor path traversal to PHP file write/RCE via data-v-save-global
Weaknesses CWE-22
CWE-94
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T20:04:55.345Z

Reserved: 2026-06-15T19:45:23.540Z

Link: CVE-2026-54612

cve-icon Vulnrichment

Updated: 2026-09-18T20:04:51.850Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:17:01.377

Modified: 2026-09-18T20:17:16.897

Link: CVE-2026-54612

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T01:30:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')