๐Ÿ” CVE Alert

CVE-2026-54507

UNKNOWN 0.0

Vvveb oEmbedProxy vulnerable to server-side request forgery

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, the oEmbedProxy() handler in admin/controller/editor/editor.php accepts an attacker-controlled url parameter and passes it to getUrl(), while validateUrl() in system/functions.php checks only the hostname string and does not validate its resolved addresses. An authenticated admin-panel user with editor/* permission can invoke GET /admin/index.php?module=editor/editor&action=oEmbedProxy with a dotted hostname or normalized loopback form that resolves to a private, loopback, link-local, or reserved address, causing the server to issue an HTTP or HTTPS request and return the response body. Storefront users and anonymous visitors cannot invoke the endpoint, but no CSRF token is required because the action uses GET. This can disclose internal service responses or cloud instance metadata and associated credentials. This issue is fixed in version 1.0.8.5.

CWE CWE-918
Vendor givanz
Product vvveb
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for givanz vvveb

Be the first to know when new unknown vulnerabilities affecting givanz vvveb are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

givanz / Vvveb
< 1.0.8.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/givanz/Vvveb/security/advisories/GHSA-xxp7-59p2-4jr8 github.com: https://github.com/givanz/Vvveb/commit/bd280f5ce136f6da22c873fb1eea9cad8741e623 github.com: https://github.com/givanz/Vvveb/releases/tag/1.0.8.5