Junglewise Threat Intelligence

CVE-2026-54507: Vvveb oEmbedProxy SSRF in editor handler

CVE-2026-54507 · Severity: info · CVSS 6.5 · Published 2026-09-17

Technologies: Vvveb. Vendors: Vvveb.

Executive brief

Vvveb is a CMS and page builder used to create websites and online stores. An authenticated editor with admin-panel access can exploit a server-side request forgery (SSRF) vulnerability in the page editor to make the server fetch URLs pointing to internal services or cloud metadata endpoints, potentially exposing sensitive configuration, credentials, or service responses that should not be publicly accessible.

Technical details

The oEmbedProxy() handler in admin/controller/editor/editor.php accepts an attacker-controlled url parameter and passes it to getUrl() without proper validation. The validateUrl() function in system/functions.php checks only the hostname string and does not validate the resolved IP address. An authenticated admin-panel user with editor/* permission can invoke GET /admin/index.php?module=editor/editor&action=oEmbedProxy with a crafted hostname that resolves to private, loopback, link-local, or reserved addresses, causing the server to issue HTTP/HTTPS requests and return response bodies. No CSRF token is required because the action uses GET. The vulnerability was patched in version 1.0.8.5 by adding IP address resolution checks in validateUrl().

Affected products

  • Vvveb Vvveb prior to 1.0.8.5

Timeline

  • 2026-09-17: disclosed
  • 2026-06-07: patched: Version 1.0.8.5 released with IP validation fix

References

Related threats