CVE Feed

    Dashboard / CVE / CVE-2026-34429

    CVE-2026-34429

    Vvveb prior to 1.0.8.1 contains a stored cross-site scripting vulnerability that allows authenticated users with media upload and rename permissions to execute arbitrary JavaScript by bypassing MIME type validation and renaming uploaded files to executable extensions. Attackers can prepend a GIF89a header to HTML/JavaScript payloads to bypass upload validation, rename the file to .html extension, and execute malicious scripts in an administrator's browser session to create backdoor accounts and upload malicious plugins for remote code execution.

    Published:Apr 20, 2026
    Last Modified:Jul 28, 2026
    EPS:Apr 20, 2026
    EPSS Score:0.00281
    CVSS Score:5.4

    Affected Products

    Vendor
    Givanz
    Product
    Vvveb
    Vendor
    Vvveb
    Product
    Vvveb

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High