Description
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, getThemeFolder() in admin/controller/editor/revisions.php returns the attacker-controlled theme parameter without sanitization, and backupFolder() concatenates it beneath DIR_THEMES before editor/revisions/load or editor/revisions/delete operates on a named .html file. sanitizeBackupFileName() strips traversal characters only from the separate file parameter and does not protect the theme directory component. An authenticated user with the default Editor role and editor/* permission can submit traversal sequences that redirect file_get_contents() or unlink() to a reachable backup subdirectory outside the web root. A valid admin session and CSRF token are required, the read is limited to .html files in backup directories, and deletion additionally requires filesystem write permission. This can disclose sensitive exported site content or remove backup data. This issue is fixed in version 1.0.8.5.
Published: 2026-09-17
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Exposure or Deletion via Path Traversal
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a path traversal flaw in Vvveb’s revisions controller. An attacker able to supply an unsanitized theme value can cause the application to construct file paths that traverse outside the intended themes directory, allowing an authenticated user to read or delete .html backup files. This can expose sensitive site content or remove backup data. The flaw aligns with CWE‑22, impacting confidentiality and integrity through improper input validation.

Affected Systems

Vvveb CMS from vendor givanz, versions prior to 1.0.8.5. The issue is present in admin/controller/editor/revisions.php and has been fixed in release 1.0.8.5.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate risk while the EPSS score of less than 1% denotes very low probability of exploitation; the vulnerability is not listed in CISA KEV. Exploitation requires a valid admin session, the default Editor role, and a correct CSRF token. Once those prerequisites are met, an attacker can traverse directories via the theme parameter to read or delete backup .html files located in subdirectories of DIR_THEMES. The path traversal is limited to backup directories but still lets the attacker reveal site content or delete backups.

Generated by OpenCVE AI on September 19, 2026 at 01:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Vvveb to version 1.0.8.5 or later to apply the fix.
  • Remove or restrict the editor role or editor/* permission that allows access to revisions and backup files.
  • Move the backup directories outside the web root or set restrictive filesystem permissions to prevent reading or deleting backup files.

Generated by OpenCVE AI on September 19, 2026 at 01:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Givanz
Givanz vvveb
Vendors & Products Givanz
Givanz vvveb

Thu, 17 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, getThemeFolder() in admin/controller/editor/revisions.php returns the attacker-controlled theme parameter without sanitization, and backupFolder() concatenates it beneath DIR_THEMES before editor/revisions/load or editor/revisions/delete operates on a named .html file. sanitizeBackupFileName() strips traversal characters only from the separate file parameter and does not protect the theme directory component. An authenticated user with the default Editor role and editor/* permission can submit traversal sequences that redirect file_get_contents() or unlink() to a reachable backup subdirectory outside the web root. A valid admin session and CSRF token are required, the read is limited to .html files in backup directories, and deletion additionally requires filesystem write permission. This can disclose sensitive exported site content or remove backup data. This issue is fixed in version 1.0.8.5.
Title Vvveb: Path Traversal in Revision Backup Reader/Deleter via Unsanitized theme Parameter
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T01:55:30.837Z

Reserved: 2026-06-15T19:45:23.540Z

Link: CVE-2026-54613

cve-icon Vulnrichment

Updated: 2026-09-22T01:55:26.699Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:17:01.533

Modified: 2026-09-22T02:16:32.197

Link: CVE-2026-54613

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T01:30:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')