Description
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's HTML sanitizer fails to strip event-handler attributes when a tag carries a greater-than character inside a quoted attribute value. A low-privilege content author (default role author or contributor) can store a payload in post or product content that runs JavaScript in a browser of every visitor and of any administrator who views or previews that content, which opens a path to admin account takeover. This issue has been patched in version 1.0.8.6.
Published: 2026-10-01
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Stored XSS enabling administrator takeover
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw caused by the HTML sanitizer overlooking event‑handler attributes when a tag contains a quoted greater‑than character. The flaw allows a low‑privilege content author, such as an author or contributor, to embed JavaScript that executes in the browsers of all site visitors and any site administrator who views or previews the affected content. Execution of the script can lead to hijacking of an administrator account if the attacker can conduct account takeover or other privileged actions. This defect is classified as CWE‑79.

Affected Systems

Vvveb CMS produced by Givanz, versions earlier than 1.0.8.6. Any installation of Vvveb that has not been upgraded to 1.0.8.6 or later is vulnerable.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is via content creation by users with author or contributor roles, who can store malicious payloads that bypass the sanitization process. The stored payload is then rendered as part of page content, causing arbitrary script execution in the browsers of every visitor and administrator. This can directly lead to privilege escalation and account takeover.

Generated by OpenCVE AI on October 1, 2026 at 20:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Vvveb to version 1.0.8.6 or later
  • If an immediate upgrade is not possible, review and sanitize existing posts, products, or other content for embedded JavaScript or event‑handler attributes and remove or escape them
  • Limit author and contributor roles from embedding arbitrary HTML or use the system’s content moderation controls to prevent execution of script tags

Generated by OpenCVE AI on October 1, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Givanz
Givanz vvveb
Vendors & Products Givanz
Givanz vvveb

Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's HTML sanitizer fails to strip event-handler attributes when a tag carries a greater-than character inside a quoted attribute value. A low-privilege content author (default role author or contributor) can store a payload in post or product content that runs JavaScript in a browser of every visitor and of any administrator who views or previews that content, which opens a path to admin account takeover. This issue has been patched in version 1.0.8.6.
Title Vvveb: Stored XSS in Vvveb via sanitizeHTML() filter bypass using a quoted greater-than character
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-01T19:23:19.200Z

Reserved: 2026-06-16T16:16:32.628Z

Link: CVE-2026-55230

cve-icon Vulnrichment

Updated: 2026-10-01T19:23:12.085Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T19:17:21.503

Modified: 2026-10-01T20:17:25.737

Link: CVE-2026-55230

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T20:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')