Executive brief
Vvveb CMS, a website building and content management platform, contains a security flaw in its visual editor. An attacker can trick a user (such as an administrator) into clicking a malicious link, which then executes unauthorized code in their browser. This could allow the attacker to steal login sessions, take over accounts, or modify website content.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Vvveb CMS due to insufficient authentication and input sanitization in the visual editor's preview functionality. The 'isEditor()' function in 'system/functions.php' incorrectly validates editor status based solely on the presence of the 'r' query parameter without verifying sessions or roles. Consequently, the view handler in 'system/core/view.php' accepts raw HTML from the 'html' POST parameter and injects it directly into the response body when '_component_ajax' is present. An unauthenticated attacker can exploit this by crafting a malicious link or auto-submitting form to execute arbitrary JavaScript in a victim's browser. This vulnerability was patched in version 1.0.8.2 by adding proper admin and user key checks.
Affected products
- givanz Vvveb CMS before 1.0.8.2
Timeline
- 2026-04-27: other: Vulnerability validated
- 2026-05-04: patched: Fix committed and version 1.0.8.2 released
- 2026-05-04: advisory: GitHub Security Advisory published
- 2026-05-07: disclosed: CVE published to NVD