CVE-2026-41929: medium-severity vulnerability in givanz Vvveb
Vvveb < 1.0.8.2 Unauthenticated Reflected XSS via Visual Editor
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.1epss 0.3%
exploitation probability
0.3%top 75% of all CVEs
observed exploitation
nono source reports it
Vvveb before 1.0.8.2 contains an unauthenticated reflected cross-site scripting vulnerability in the visual editor preview renderer that allows attackers to execute arbitrary JavaScript by manipulating the r query parameter and _component_ajax POST parameter. Attackers can craft a malicious link or auto-submitted form that causes victims to execute attacker-controlled JavaScript in the context of the Vvveb origin, as the gating function isEditor() performs no session, role, or token verification and the view handler injects raw HTML POST body content without sanitization.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Affected products
givanz · VvvebRelated CVEs — givanz Vvveb
In the same product, most dangerous first.
CVE-2025-8517MEDIUMgivanz Vvveb session fixiationEPSS 2.2%CVE-2025-8518MEDIUMgivanz Vvveb Code Editor code.php save code injectionEPSS 2.1%CVE-2026-39918CRITICALVvveb < 1.0.8.1 Code Injection via Installation EndpointEPSS 1.1%CVE-2026-41938HIGHVvveb < 1.0.8.2 RCE via Media Upload HandlerEPSS 1.0%CVE-2026-34427HIGHVvveb < 1.0.8.1 Privilege Escalation via admin/user/saveEPSS 1.0%CVE-2026-41934HIGHVvveb < 1.0.8.2 Authenticated RCE via Code EditorEPSS 1.0%
References
https://github.com/givanz/Vvveb/commit/54a9e846fb94192f1b31ae81d81d25c874662e6ahttps://github.com/givanz/Vvveb/releases/tag/1.0.8.2https://github.com/givanz/Vvveb/security/advisories/GHSA-wwmv-4g9g-p48ghttps://www.vulncheck.com/advisories/vvveb-unauthenticated-reflected-xss-via-visual-editor