Junglewise Threat Intelligence

CVE-2026-45622: Vvveb CMS reflected XSS in product return form

CVE-2026-45622 · Severity: info · CVSS 5.3 · Published 2026-05-15

Technologies: Givanz Vvveb CMS. Vendors: Givanz.

Executive brief

Vvveb CMS is a content management system used for building websites and e-commerce stores. A security flaw in the product return form allows attackers to execute malicious scripts in a user's web browser. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information when a user interacts with a specially crafted link or form.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Vvveb CMS versions prior to 1.0.8.3. The vulnerability is located in the public product return form (`/index.php?module=user/return-form&action=save`) within the `customer_order_id` POST parameter. When an order lookup fails, the application inserts the raw input into an "Order %s not found!" error message using `sprintf` and renders it in the frontend template without proper HTML escaping. An unauthenticated attacker can exploit this by tricking a user into submitting a crafted payload, leading to arbitrary script execution in the context of the user's browser session. The issue is fixed in version 1.0.8.3.

Affected products

  • givanz Vvveb CMS Prior to 1.0.8.3

Timeline

  • 2026-05-13: advisory: GitHub Security Advisory published
  • 2026-05-15: disclosed: CVE published to NVD
  • 2026-05-15: patched: Vulnerability fixed in version 1.0.8.3

References

Related threats