๐Ÿ” CVE Alert

CVE-2026-45622

UNKNOWN 0.0

Vvveb: Unauthenticated reflected XSS in public product return form via customer_order_id

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, there is an unauthenticated reflected cross-site scripting (XSS) issue in the public product return form in Vvveb CMS. The customer_order_id POST parameter is inserted into the Order %s not found! error message when the order lookup fails, and that message is rendered in the frontend template without HTML escaping. As a result, attacker-controlled HTML/JavaScript executes in the submitting user's browser. This vulnerability is fixed in 1.0.8.3.

CWE CWE-79
Vendor givanz
Product vvveb
Published May 15, 2026
Stay Ahead of the Next One

Get instant alerts for givanz vvveb

Be the first to know when new unknown vulnerabilities affecting givanz vvveb are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

givanz / Vvveb
< 1.0.8.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/givanz/Vvveb/security/advisories/GHSA-3xwm-8f6m-cfc6