CVE 6.9 MEDIUM

Vvveb < 1.0.8.3 Directory Listing Information Disclosure_CVE-2026-41933

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Vvveb before 1.0.8.3 contains a directory listing information disclosure vulnerability that allows unauthenticated attackers to enumerate files and directories by accessing multiple paths lacking proper index directives in .htaccess files. Attackers can access directories such as admin asset paths, plugins, themes, and media folders to view filenames, file sizes, modification timestamps, and unrendered admin templates containing sensitive route maps.

Basic Information

ID CVE-2026-41933
Source VulnCheck
Published May 14, 2026 at 14:23
Modified May 14, 2026 at 15:59

Affected Product

Vendor givanz
Product Vvveb
Affected Versions givanz Vvveb 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.