Givanz · Vvveb · CVE-2026-41933
**Name of the Vulnerable Software and Affected Versions**
Vvveb versions prior to 1.0.8.3
**Description**
An information disclosure issue allows unauthenticated attackers to enumerate files and directories. This occurs because multiple paths lack proper index directives in .htaccess files, which are configuration files used by Apache web servers to control directory-level settings. Attackers can access admin asset paths, plugins, themes, and media folders to view filenames, file sizes, modification timestamps, and unrendered admin templates that contain sensitive route maps.
**Recommendations**
Update Vvveb to version 1.0.8.3 or later.