Sceawere

Vulnerability Detail

CVE-2026-55230UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Vvveb Stored XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.7
Creation Date
1d ago
Vendor
givanz
Product
Vvveb
Attack Type
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's HTML sanitizer fails to strip event-handler attributes when a tag carries a greater-than character inside a quoted attribute value. A low-privilege content author (default role author or contributor) can store a payload in post or product content that runs JavaScript in a browser of every visitor and of any administrator who views or previews that content, which opens a path to admin account takeover. This issue has been patched in version 1.0.8.6.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.7",
  "pubDate": "2026-10-01T19:17:21.503Z",
  "pubdate": "2026-10-01T19:17:21.503Z",
  "executiveSummary": "Vvveb prior to version 1.0.8.6 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability residing within its HTML sanitization logic.\nThe vulnerability allows an authenticated attacker, such as a user with author or contributor privileges, to inject malicious JavaScript into web content.\nBy manipulating attribute syntax to bypass the sanitizer, the attacker can execute arbitrary scripts in the browsers of other users, including site administrators.\nThis vulnerability poses a critical risk as it enables unauthorized script execution, facilitating actions such as session hijacking, administrative account takeover, or defacement.\nSuccessful exploitation requires the attacker to possess low-level content creation permissions, allowing them to embed a payload within posts or products.\nThe impact is significant, as the payload executes whenever a visitor or administrator interacts with the compromised content, effectively compromising the integrity and security of the Vvveb installation.",
  "technicalDetails": "The vulnerability originates from an implementation flaw within the Vvveb HTML sanitization engine. The sanitizer fails to correctly parse and neutralize event-handler attributes (e.g., onerror, onload, onclick) when a malicious HTML tag includes a greater-than character ('>') within a quoted attribute value.\nThe root cause is a deficiency in the regex-based or string-parsing logic used by the sanitizer, which terminates prematurely or misinterprets the structure of the HTML tag when specific character sequences are injected.\nAn attacker can exploit this by crafting a payload where an event handler is included inside an attribute value, accompanied by a '>', which tricks the sanitizer into believing the tag has prematurely closed or ignoring the subsequent attribute payload. This allows for the injection of executable JavaScript code that is subsequently rendered by the browser.\nThe attack flow proceeds as follows: First, an authenticated user with author or contributor rights crafts a post or product description containing the obfuscated HTML payload. Second, the Vvveb backend processes this content through the flawed sanitizer, which fails to strip the event handler due to the payload's structural bypass. Third, the malicious script is stored in the application database. Fourth, whenever a victim (visitor or administrator) views the specific page, post, or product preview, the browser executes the stored JavaScript code in the context of the victim's session.\nBecause the payload runs in the context of the user's browser, the attacker can perform actions on behalf of the victim. If an administrator views the content, the attacker can leverage the XSS to execute administrative functions, steal session cookies, or modify system settings to achieve full account takeover.\nThe vulnerability affects all Vvveb instances prior to version 1.0.8.6. Exploitation does not require external network access beyond the application's interface, as the attacker must already be authenticated with standard content-creation privileges to inject the payload into the system's database. The technical failure lies in the incorrect handling of attribute-bound closures, which is a common pitfall in custom HTML sanitization routines that lack a robust, DOM-based parsing approach."
}
CVE-2026-55230: Vvveb Stored XSS Vulnerability (HIGH Severity, CVSS: 8.7) | Sceawere