SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-49222

HIGH · CVSS 7.6 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Vvveb CMS versions prior to 1.0.8.4 are vulnerable to unauthorized access, allowing low-privileged vendors to manage product questions associated with other vendors' products. This flaw can lead to exposure of sensitive question content, unauthorized modifications, and potential deletion of questions, compromising the integrity of product Q&A sections. Organizations using Vvveb should prioritize upgrading to version 1.0.8.4 to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-49222
Severity
HIGH
CVSS
7.6
EPSS
0.38%

Original NVD Description

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product question operations allow a low-privileged Vendor to manage questions under another Vendor's products. The admin/sql/sqlite/product_question.sql queries accept a caller-controlled product_question_id and do not verify product_question.product_id against product.admin_id for the current admin_id. An attacker can read pending question content and moderation data, change question status, edit question content, or delete questions, manipulating product Q&A visibility and integrity. This issue is fixed in version 1.0.8.4.