Junglewise Threat Intelligence

CVE-2026-45616: Vvveb CMS stored XSS in post editor

CVE-2026-45616 · Severity: info · CVSS 5.1 · Published 2026-05-15

Vendors: Vvveb.

Executive brief

Vvveb CMS, a platform used for building websites and e-commerce stores, contains a security flaw that allows users with 'Editor' permissions to target site administrators. By saving malicious code within a post, an attacker can hijack the session of an administrator who later opens that post for editing. This could lead to full site takeover, including the creation of unauthorized admin accounts or the theft of customer data.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Vvveb CMS prior to version 1.0.8.3 due to improper sanitization of HTML event-handler attributes in post content. An attacker with 'Editor' role permissions can inject malicious JavaScript (e.g., via 'onerror' attributes) into the post content field at /admin/index.php?module=content/post. The payload executes when a higher-privileged user, such as an Administrator, opens the affected post in the admin editor. This allows for session cookie theft, account takeover, and unauthorized administrative actions. The issue is resolved in version 1.0.8.3 by implementing stricter server-side HTML sanitization.

Affected products

  • Vvveb Vvveb CMS < 1.0.8.3

Timeline

  • 2026-05-13: advisory: GitHub security advisory published by vendor
  • 2026-05-15: disclosed: CVE published to NVD dataset
  • 2026-05-15: patched: Fixed in version 1.0.8.3

References