CVE-2026-41936
Deferred Deferred - Pending Action
XXE Injection in Vvveb CMS Admin Tools

Publication date: 2026-05-06

Last updated on: 2026-05-06

Assigner: VulnCheck

Description
Vvveb before version 1.0.8.2 contains an XML external entity (XXE) injection vulnerability in the admin Tools/Import feature that allows authenticated site_admin users to read arbitrary files and modify database records. Attackers can exploit the XML parser configuration in system/import/xml.php to inject file:// or php://filter entity references that are resolved and persisted into the application database, enabling arbitrary file disclosure and administrator password hash overwriting for privilege escalation.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-06
Last Modified
2026-05-06
Generated
2026-06-16
AI Q&A
2026-05-06
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
vvveb vvveb to 1.0.8.2 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-611 The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

Vvveb before version 1.0.8.2 contains an XML external entity (XXE) injection vulnerability in the admin Tools/Import feature. This vulnerability allows authenticated site_admin users to exploit the XML parser in system/import/xml.php by injecting file:// or php://filter entity references. These injected entities are resolved and saved into the application database, enabling attackers to read arbitrary files and modify database records.

Impact Analysis

This vulnerability can have serious impacts including arbitrary file disclosure, which means attackers can read sensitive files on the server. Additionally, attackers can overwrite administrator password hashes in the database, potentially escalating their privileges to gain full administrative control over the application.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-41936. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart