Junglewise Threat Intelligence

CVE-2026-54612: Vvveb CMS arbitrary file write and PHP execution

CVE-2026-54612 · Severity: high · CVSS 8.8 · Published 2026-09-17

Technologies: Vvveb. Vendors: Vvveb.

Executive brief

Vvveb is a page builder CMS used to create websites, blogs, and ecommerce stores. A flaw in the global elements save function allows authenticated editors to write arbitrary PHP files to web-accessible directories, leading to persistent webshell placement and complete compromise of application confidentiality, integrity, and availability.

Technical details

The vulnerability exists in saveGlobalElements() within admin/controller/editor/global-trait.php, which concatenates user-controlled file paths from the data-v-save-global parameter directly to the theme directory without proper sanitization before passing to loadHTMLFile() and file_put_contents(). An authenticated user with the default Editor role and editor/* permission can submit crafted HTML to module=editor/editor&action=save to traverse outside the theme directory and overwrite existing writable PHP files. If web-accessible, the attacker can leverage the shipped public/vadmin/index.php entrypoint to execute editor-controlled PHP code. The fix in version 1.0.8.5 adds path sanitization and removes the editor/* permission for the Editor role.

Affected products

  • Vvveb Vvveb 1.0.0 through 1.0.8.4

Timeline

  • 2026-09-17: disclosed
  • 2026-06-07: patched: Version 1.0.8.5 released with sanitization fix

References

Related threats