CVE-2026-45622: Vvveb: Unauthenticated reflected XSS in public product return form via customer_order_id
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, there is an unauthenticated reflected cross-site scripting (XSS) issue in the public product return form in Vvveb CMS. The customerorderid POST parameter is inserted into the Order %s not found! error message when the order lookup fails, and that message is rendered in the frontend template without HTML escaping. As a result, attacker-controlled HTML/JavaScript executes in the submitting user's browser. This vulnerability is fixed in 1.0.8.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45622?
CVE-2026-45622 has a severity rating of medium due to its potential for unauthenticated reflected cross-site scripting (XSS).
How do I fix CVE-2026-45622?
To fix CVE-2026-45622, upgrade Vvveb CMS to version 1.0.8.3 or later.
What products are affected by CVE-2026-45622?
CVE-2026-45622 affects the Vvveb CMS versions prior to 1.0.8.3.
What type of vulnerability is CVE-2026-45622?
CVE-2026-45622 is categorized as an unauthenticated reflected cross-site scripting (XSS) vulnerability.
Who is the vendor of the affected software for CVE-2026-45622?
The vendor of the affected software for CVE-2026-45622 is Vvveb.