Junglewise Threat Intelligence

CVE-2026-54613: Vvveb path traversal in backup file handling via theme parameter

CVE-2026-54613 · Severity: medium · CVSS 5.4 · Published 2026-09-17

Technologies: Vvveb. Vendors: Vvveb.

Executive brief

Vvveb is a CMS and page builder for creating websites and e-commerce stores. An authenticated editor can exploit insufficient sanitization of the theme parameter to access or delete backup files outside the intended theme directory, potentially exposing sensitive exported site content or removing backup data.

Technical details

A path traversal vulnerability exists in admin/controller/editor/revisions.php where the getThemeFolder() function returns an attacker-controlled theme parameter without sanitization. The vulnerability allows authenticated users with the Editor role to submit traversal sequences (e.g., ../) that redirect file_get_contents() or unlink() operations to backup subdirectories outside the web root. An admin session and valid CSRF token are required; reads are limited to .html files in backup directories, and deletion requires filesystem write permission. The root cause is insufficient input validation on the theme parameter before concatenation with DIR_THEMES. The fix, applied in version 1.0.8.5, applies sanitizeFileName() to the theme parameter to strip traversal characters.

Affected products

  • Vvveb Vvveb prior to 1.0.8.5

Timeline

  • 2026-09-17: disclosed: CVE-2026-54613 published
  • 2026-06-07: patched: Fixed in version 1.0.8.5

References

Related threats