216.73.217.22

CVE-2026-39918

· Published 20/04/2026 16:16 · Modified 20/04/2026 18:54

Labels: CVE-2026-39918 2026-04-20CVE-2026-39918CWE-94[email protected]

Essential information

Published
20/04/2026 16:16
Modified
20/04/2026 18:54
Author
Creator
CVSS
9.2 CRITICAL (v3) 9.2 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parameter is written unsanitized into the env.php configuration file without escaping or validation. Attackers can inject arbitrary PHP code by breaking out of the string context in the define statement to achieve unauthenticated remote code execution as the web server user.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
vvveb / vvveb cpe:2.3:a:vvveb:vvveb:<1.0.8.1:*:*:*:*:*:*:*

References