{"id":"CVE-2026-54506","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-54506","summary":"Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, app/controller/user/profile.php accepts the user[bio] field…","details":"Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, app/controller/user/profile.php accepts the user[bio] field and passes stored content through sanitizeHTML() in system/functions.php, whose on* event-handler regular expression omits the forward-slash delimiter and whose do-while condition compares the string to itself, so forbidden nested tags are removed only once. An Author-role or higher user can submit solidus-prefixed event-handler markup or nested forbidden tags that survive sanitization. The stored bio is rendered without sufficient output encoding on /author/{username}, in the admin user-management view, and potentially in comment displays, causing attacker-controlled JavaScript to execute when unauthenticated visitors, administrators, or other users view the content. This can expose browser-session data and permit victim-context account actions, defacement, or phishing. This issue is fixed in version 1.0.8.5.","published":"2026-09-17T22:17:00.537","modified":"2026-09-17T22:17:00.673","cvss":{"score":7.6,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/givanz/Vvveb/commit/20a01ef08559ffdc97205edeecde86c8ea27e567","label":"givanz/Vvveb@20a01ef"},"references":[{"type":"WEB","url":"https://github.com/givanz/Vvveb/commit/20a01ef08559ffdc97205edeecde86c8ea27e567"},{"type":"WEB","url":"https://github.com/givanz/Vvveb/releases/tag/1.0.8.5"},{"type":"WEB","url":"https://github.com/givanz/Vvveb/security/advisories/GHSA-5cg7-phhv-4qjr"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-17T22:17:00.673"}}