Vvveb before 1.0.8.2 contains an unauthenticated reflected cross-site scripting vulnerability in the visual editor preview renderer that allows attackers to execute arbitrary JavaScript by manipulating the r query parameter and _component_ajax POST parameter. Attackers can craft a malicious link or auto-submitted form that causes victims to execute attacker-controlled JavaScript in the context of the Vvveb origin, as the gating function isEditor() performs no session, role, or token verification and the view handler injects raw HTML POST body content without sanitization.
Metrics
Affected Vendors & Products
References
History
Thu, 07 May 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Givanz
Givanz vvveb |
|
| Vendors & Products |
Givanz
Givanz vvveb |
Thu, 07 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vvveb before 1.0.8.2 contains an unauthenticated reflected cross-site scripting vulnerability in the visual editor preview renderer that allows attackers to execute arbitrary JavaScript by manipulating the r query parameter and _component_ajax POST parameter. Attackers can craft a malicious link or auto-submitted form that causes victims to execute attacker-controlled JavaScript in the context of the Vvveb origin, as the gating function isEditor() performs no session, role, or token verification and the view handler injects raw HTML POST body content without sanitization. | |
| Title | Vvveb < 1.0.8.2 Unauthenticated Reflected XSS via Visual Editor | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-05-07T21:08:50.762Z
Updated: 2026-05-07T21:08:50.762Z
Reserved: 2026-04-22T18:50:43.620Z
Link: CVE-2026-41929
No data.
Status : Received
Published: 2026-05-07T22:16:35.450
Modified: 2026-05-07T22:16:35.450
Link: CVE-2026-41929
No data.