CVE-2026-41933 Details
Description
Vvveb before 1.0.8.3 contains a directory listing information disclosure vulnerability that allows unauthenticated attackers to enumerate files and directories by accessing multiple paths lacking proper index directives in .htaccess files. Attackers can access directories such as admin asset paths, plugins, themes, and media folders to view filenames, file sizes, modification timestamps, and unrendered admin templates containing sensitive route maps.
A directory listing information disclosure vulnerability has been identified in Vvveb versions prior to 1.0.8.3. This vulnerability allows unauthenticated attackers to enumerate files and directories by accessing multiple paths that lack proper index directives in .htaccess files. Exploitation of this vulnerability enables access to directories such as admin asset paths, plugins, themes, and media folders, where attackers can view filenames, file sizes, modification timestamps, and unrendered admin templates containing sensitive route maps.
Users can update to Vvveb version 1.0.8.3 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 14, 2026CISA-ADP
Assessed May 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/givanz/Vvveb/commit/96ae04c5e4a295e281adc1d02d77444173653deb | [email protected] | Source CodeVendor |
| https://github.com/givanz/Vvveb/releases/tag/1.0.8.3 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/vvveb-directory-listing-information-disclosure | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-548 | Exposure of Information Through Directory Listing | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Vvveb | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 14, 2026 | New CVE Received | [email protected] |
Volerion