PT-2026-41370 · Givanz · Vvveb

Published

2026-05-15

·

Updated

2026-05-15

·

CVE-2026-46407

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the backend admin/auth-token endpoint allows an authenticated administrator to load another administrator's REST API token list by supplying that user's admin id. This can disclose sensitive API tokens belonging to other administrators. This vulnerability is fixed in 1.0.8.3.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-46407

Affected Products

Vvveb