CVE-2026-6249 Details
Description
Vvveb CMS 1.0.8.2 contains a remote code execution vulnerability in its media upload handler that allows authenticated attackers to execute arbitrary operating system commands by uploading a PHP webshell with a .phtml extension. Attackers can bypass the extension deny-list and upload malicious files to the publicly accessible media directory, then request the file over HTTP to achieve full server compromise.
A remote code execution vulnerability has been identified in Vvveb CMS version 1.0.8. This issue arises in the media upload handler, where authenticated attackers can upload PHP web shells with a .phtml extension, bypassing the extension deny-list. The uploaded files are placed in a publicly accessible media directory. Once the malicious file is uploaded, it can be accessed over HTTP, allowing the attacker to execute arbitrary operating system commands and potentially compromise the entire server.
Users can update to Vvveb CMS version 1.0.8.1, which addresses this vulnerability by adding .phtml to the extension deny-list for media uploads.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 20, 2026CISA-ADP
Assessed Apr 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/givanz/Vvveb/commit/23ac0e8c758d80f3c4d9224763c8b2359648270e | [email protected] | Source CodeVendor |
| https://www.vulncheck.com/advisories/vvveb-cms-remote-code-execution-via-media-upload | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Vvveb CMS | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 6, 2026 | CVE Modified | [email protected] |
| Apr 20, 2026 | New CVE Received | [email protected] |
Volerion