SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-49223

HIGH · CVSS 7.6 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Vvveb CMS versions prior to 1.0.8.4 are vulnerable to unauthorized access in the product review management system, allowing low-privileged vendors to manipulate reviews associated with other vendors' products. This vulnerability can lead to the exposure of sensitive review information, as well as the ability to alter or delete reviews, compromising the integrity of product visibility and ratings. Organizations using Vvveb should prioritize upgrading to version 1.0.8.4 to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-49223
Severity
HIGH
CVSS
7.6
EPSS
0.38%

Original NVD Description

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product review operations allow a low-privileged Vendor to manage reviews under another Vendor's products. The admin/sql/sqlite/product_review.sql queries accept a caller-controlled product_review_id and do not verify product_review.product_id against product.admin_id for the current admin_id. An attacker can read pending review content, ratings, author information, and moderation state, change review status, edit review content, or delete reviews, manipulating product review visibility and integrity. This issue is fixed in version 1.0.8.4.