Junglewise Threat Intelligence

CVE-2026-41937: Givanz Vvveb unrestricted file upload in plugin upload endpoint

CVE-2026-41937 · Severity: high · CVSS 7.2 · Published 2026-05-14

Technologies: Givanz VvvebJs. Vendors: Givanz.

Executive brief

Vvveb, an open-source content management system, contains a security flaw in its plugin management system. An administrative user can upload a specially crafted plugin file containing malicious code, which can then be triggered remotely without further authentication. This allows an attacker with high-level access to take full control of the web server, potentially leading to data theft or complete service disruption.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in the plugin upload endpoint of Vvveb. A user with super_admin privileges can upload a malicious ZIP archive containing a 'plugin.php' file with a valid Slug header and a 'public/index.php' file containing arbitrary PHP code. Because the application does not properly validate the contents of the uploaded plugin's public directory, the PHP code can be executed by the web server user through a subsequent unauthenticated HTTP request to the plugin's public path. The vulnerability is addressed in version 1.0.8.3 by validating plugin uploads and ensuring PHP files are not exposed in public folders.

Affected products

  • givanz Vvveb before 1.0.8.3

Timeline

  • 2026-05-11: patched: Fix committed to repository
  • 2026-05-13: advisory: Version 1.0.8.3 released
  • 2026-05-14: disclosed: CVE published

References

Related threats