CVE-2026-41937 Details
Description
Vvveb before 1.0.8.3 contains an unrestricted file upload vulnerability in the plugin upload endpoint that allows super_admin users to execute arbitrary PHP code by uploading a malicious plugin ZIP file. Attackers can craft a ZIP containing a plugin.php with a valid Slug header and a public/index.php file with arbitrary PHP code, which executes as the web server user once accessed via subsequent unauthenticated HTTP requests to the plugin's public path.
A vulnerability allowing unrestricted file uploads has been identified in Vvveb versions prior to 1.0.8.3. This issue resides in the plugin upload endpoint, where super_admin users can upload malicious plugin ZIP files that execute arbitrary PHP code. The exploitation involves crafting a ZIP file that includes a plugin.php file with a valid Slug header and a public/index.php file containing the PHP code. Once uploaded, the code executes as the web server user in response to unauthenticated HTTP requests directed to the plugin's public path.
Users are advised to update to Vvveb version 1.0.8.3 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 14, 2026CISA-ADP
Assessed May 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/givanz/Vvveb/commit/04f0294350ec429e307cd31c2e777a4797c868d6 | [email protected] | Source CodeVendor |
| https://github.com/givanz/Vvveb/releases/tag/1.0.8.3 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/vvveb-unrestricted-file-upload-rce-via-plugin-upload | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
| CWE-61 | UNIX Symbolic Link (Symlink) Following | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Vvveb | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | CVE Modified | [email protected] |
| May 14, 2026 | New CVE Received | [email protected] |
Volerion