CVE 8.7 HIGH

Vvveb < 1.0.8.2 Authenticated RCE via Code Editor_CVE-2026-41934

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Vvveb before version 1.0.8.2 contains an authenticated remote code execution vulnerability in the admin code editor that allows low-privilege authenticated users to execute arbitrary code by exploiting insufficient file extension restrictions. Attackers with editor, author, contributor, or site_admin roles can write a malicious .htaccess file to map arbitrary extensions to the PHP handler, then upload PHP code with that extension to achieve unauthenticated remote code execution when the file is accessed via HTTP.

AI Analysis

Authenticated remote code execution vulnerability in the admin code editor

Basic Information

ID CVE-2026-41934
Source VulnCheck
Published May 6, 2026 at 18:34
Modified May 6, 2026 at 19:16

Affected Product

Vendor givanz
Product Vvveb
Affected Versions givanz Vvveb 0

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor givanz
Product Vvveb
Version < 1.0.8.2

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.