CVE-2026-54506: Vvveb: Stored XSS via sanitizeHTML() bypass in user profile bio field

Published Sep 17, 2026
·
Updated

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, app/controller/user/profile.php accepts the user[bio] field and passes stored content through sanitizeHTML() in system/functions.php, whose on event-handler regular expression omits the forward-slash delimiter and whose do-while condition compares the string to itself, so forbidden nested tags are removed only once. An Author-role or higher user can submit solidus-prefixed event-handler markup or nested forbidden tags that survive sanitization. The stored bio is rendered without sufficient output encoding on /author/{username}, in the admin user-management view, and potentially in comment displays, causing attacker-controlled JavaScript to execute when unauthenticated visitors, administrators, or other users view the content. This can expose browser-session data and permit victim-context account actions, defacement, or phishing. This issue is fixed in version 1.0.8.5.

Affected Software

1 affected component
Vvveb<1.0.8.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Vvveb to a version that resolves this vulnerability.

    Fixed in 1.0.8.5

Event History

Sep 17, 2026
CVE Published
via MITRE·09:47 PM
Data Sourced
via MITRE·09:47 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue, and who is at risk when it is exploited?

An authenticated user with the Author role or higher can store malicious markup in their profile bio. Unauthenticated visitors, administrators, and other users may be affected when they view the attacker’s author page, the admin user-management view, or potentially comment displays.

2

Are default deployments affected?

The issue is in the profile bio handling and author-profile rendering paths, so deployments that allow Author-role or higher accounts to edit bios and expose the affected views are affected. Exploitation requires an attacker to have an authenticated Author-level or higher account and a victim to view the stored content.

3

What should be done if upgrading is not immediately possible?

Restrict or disable profile-bio editing for untrusted Author-level users where possible, and review existing bios for suspicious solidus-prefixed event-handler markup or nested forbidden tags. Remove suspicious stored content and limit access to affected author and administrative user-management views until the installation can be updated.

4

How can I determine whether the installation is vulnerable?

Versions prior to 1.0.8.5 are affected. Check stored user bios for markup that may have bypassed sanitization, particularly solidus-prefixed event handlers and nested forbidden tags, and review whether those bios are rendered on author pages or in administrative user-management views.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203