Skip to content
Threat Feed

Vendor

Vvveb

4 briefs RSS
critical advisory

Vvveb Hardcoded Credentials Vulnerability in phpMyAdmin Container

Vvveb versions before 1.0.8.2 contain a hardcoded credentials vulnerability in the docker-compose-apache.yaml configuration, allowing unauthenticated attackers to access the phpMyAdmin container and gain unrestricted read and write access to the Vvveb database, leading to account takeover and data manipulation.

Vvveb +1 hardcoded-credentials phpmyadmin docker vulnerability
2r 1t 1c
high advisory

Vvveb CMS XML External Entity Injection Vulnerability

Vvveb before 1.0.8.2 is vulnerable to XML external entity (XXE) injection in the admin import feature, allowing authenticated site administrators to read arbitrary files and modify database records, potentially leading to privilege escalation.

Vvveb +1 xxe vulnerability injection
2r 3t 1c
critical advisory

Vvveb Unrestricted File Upload Leads to Remote Code Execution (CVE-2026-41938)

An unrestricted file upload vulnerability in Vvveb versions before 1.0.8.2 allows authenticated users with media upload permissions to achieve remote code execution by uploading a .htaccess file to execute arbitrary PHP code via a .phtml file.

Vvveb cve-2026-41938 rce file-upload
2r 1t 1c
critical advisory

Vvveb Authenticated Remote Code Execution via .htaccess Upload (CVE-2026-41934)

Vvveb versions before 1.0.8.2 are vulnerable to authenticated remote code execution (RCE), enabling low-privilege users to execute arbitrary code by uploading a malicious .htaccess file and subsequently uploading PHP code with a mapped extension, resulting in unauthenticated RCE upon file access.

Vvveb rce htaccess CVE-2026-41934 attack.execution
2r 1t 1c