CVE-2026-55230
Deferred Deferred - Pending Action

XSS in Vvveb CMS via Event-Handler Attributes

Vulnerability report for CVE-2026-55230, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: GitHub, Inc.

Description

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's HTML sanitizer fails to strip event-handler attributes when a tag carries a greater-than character inside a quoted attribute value. A low-privilege content author (default role author or contributor) can store a payload in post or product content that runs JavaScript in a browser of every visitor and of any administrator who views or previews that content, which opens a path to admin account takeover. This issue has been patched in version 1.0.8.6.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
vvveb vvveb to 1.0.8.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stored cross-site scripting (XSS) flaw in Vvveb CMS versions before 1.0.8.6. The HTML sanitizer fails to remove event-handler attributes when a tag contains a greater-than character inside a quoted attribute value. This allows attackers with low privileges to inject malicious JavaScript into content fields like posts or products.

Detection Guidance

Check if your Vvveb version is below 1.0.8.6 by inspecting the installed package or release notes. Review HTML content fields (posts, products, bios) for suspicious event-handler attributes like onerror, onload, or onclick. Test sanitization by inputting payloads like <img src="x>" onerror="alert(1)"> and verifying if they execute in a browser.

Impact Analysis

The injected JavaScript runs in the browsers of all visitors and administrators who view the compromised content. This can lead to session hijacking, admin account takeover, or other malicious actions depending on the payload. Attackers can steal sensitive data or gain unauthorized access to the system.

Compliance Impact

This vulnerability could lead to data breaches, exposing personal or sensitive information. For GDPR, it may result in unauthorized data access or processing, violating principles of data protection. For HIPAA, it could compromise protected health information, leading to compliance violations and legal penalties.

Mitigation Strategies

Upgrade Vvveb to version 1.0.8.6 or later immediately. If upgrading is not possible, disable the vulnerable HTML sanitizer or implement additional server-side input validation and output escaping for user-generated content.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55230. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart