Vvveb Authenticated Remote Code Execution Vulnerability in Code Editor

Vulnerability

A remote code execution vulnerability has been identified in Vvveb versions prior to 1.0.8.2. This vulnerability allows low-privilege authenticated users to execute arbitrary code by exploiting inadequate file extension restrictions in the admin code editor. Attackers with editor, author, contributor, or site_admin roles can manipulate a .htaccess file to redirect certain file types to the PHP handler, enabling the execution of PHP code when the file is accessed via HTTP.

Impact

Exploitation of this vulnerability leads to unauthorized remote code execution on the server, with the executed code running under the web server's user account.

Reproduction

To reproduce this vulnerability, log into the Vvveb admin panel as a user with an affected role (editor, author, contributor, or site_admin). Navigate to the code editor and upload a .htaccess file that redirects a file extension of your choice to the PHP handler. Then, upload a file with that extension containing PHP code. When the file is accessed through the web server, the PHP code will be executed, demonstrating the remote code execution vulnerability.

Remediation

Users can update to Vvveb version 1.0.8.2, where this vulnerability has been patched.

Added: May 6, 2026, 8:53 PM
Updated: May 6, 2026, 8:53 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.2
remediation
0.0
relevance
7.6
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.