PT-2026-33774 · Vvveb · Vvveb

·

CVE-2026-34429

·

Published

2026-04-20

·

Updated

2026-04-20

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Vvveb versions prior to 1.0.8.1
Description Authenticated users with media upload and rename permissions can execute arbitrary JavaScript by bypassing MIME type validation and renaming uploaded files to executable extensions. This is achieved by prepending a GIF89a header to HTML/JavaScript payloads to bypass upload validation and then renaming the file to a '.html' extension. This allows malicious scripts to execute in an administrator's browser session, potentially leading to the creation of backdoor accounts and the upload of malicious plugins for remote code execution.
Recommendations Update to version 1.0.8.1 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34429
GHSA-2VC4-49HQ-G7F4

Affected Products

Vvveb