LiveActive security incident?Get immediate response
CVE Record

CVE-2026-41929: Vvveb < 1.0.8.2 Unauthenticated Reflected XSS via Visual Editor

Vvveb before 1.0.8.2 contains an unauthenticated reflected cross-site scripting vulnerability in the visual editor preview renderer that allows attackers to execute arbitrary JavaScript by manipulating the r query parameter and _component_ajax POST parameter. Attackers can craft a malicious link or auto-submitted form that causes victims to execute attacker-controlled JavaScript in the context of the Vvveb origin, as the gating function isEditor() performs no session, role, or token verification and the view handler injects raw HTML POST body content without sanitization.

MediumCVSS 6.1Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

Vvveb versions before 1.0.8.2 can run attacker-supplied browser code when a user follows a malicious link or encounters a crafted form. Successful abuse could expose limited data or perform actions within the victim’s Vvveb session. The victim must interact, but the attacker does not need an account.

Executive priority

Treat this as a prompt, moderate-priority update rather than an emergency. Accelerate remediation for public-facing installations or environments where administrators commonly use Vvveb. The absence of cited active exploitation lowers immediate urgency, but unauthenticated reachability and potential execution in a trusted application origin justify timely action.

Technical view

The visual editor preview renderer trusts attacker-controlled r and _component_ajax parameters. Its isEditor() gate does not verify a session, role, or token, and the view handler inserts unsanitized POST content. This creates unauthenticated reflected cross-site scripting across the Vvveb origin. CVSS 3.1 is 6.1: network-accessible, low complexity, user interaction required, and scope changed.

Likely exposure

Deployments running Vvveb before 1.0.8.2 are potentially affected, particularly where the visual editor preview endpoint is reachable by untrusted networks. Actual organizational exposure depends on deployed versions, endpoint accessibility, and whether privileged users can be induced to visit attacker-controlled content.

Exploitation context

The supplied sources do not establish active exploitation, and the CVE is not listed as KEV in the bundle. Exploitation requires victim interaction through a malicious link or automatically submitted form. Successful execution occurs in the Vvveb origin and may affect the victim’s confidentiality and integrity, but not availability according to the CVSS vector.

Researcher notes

The affected-version summary states versions before 1.0.8.2, while the structured affected entry lists only “0” and provides no CPEs. Use the vendor advisory and local version evidence when determining scope. The described fix is represented by the 1.0.8.2 release and linked patch commit; this analysis does not independently verify code behavior.

Mitigation direction

  • Upgrade affected Vvveb installations to version 1.0.8.2 or later.
  • Prioritize internet-accessible installations and systems used by privileged administrators.
  • Restrict untrusted access to the visual editor preview until upgrading.
  • Consult the vendor advisory and release notes for deployment-specific guidance.

Validation and detection

  • Inventory Vvveb deployments and confirm their installed versions.
  • Determine whether the visual editor preview is reachable from untrusted networks.
  • Review telemetry for suspicious requests involving r and _component_ajax parameters.
  • After upgrading, verify version 1.0.8.2 or later is running.
  • Confirm normal visual editor functionality without replaying potentially malicious content.
Prepared
Confidence
high
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-79: User-session and phishing behavior lookup

Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Credential and access behavior lookup

The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-41929 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
6.1 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

2CVSS vectors
3Timeline events
1ADP providers
5Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: noTechnical Impact: partial

CVSS vector scores

2 official scores

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
6.1CVSS 3.1MediumCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N2.82.7VulnCheck
5.1CVSS 4.0MediumCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:NVulnCheck

Vulnerability scoring details

Base CVSS 4.0 score

5.1Medium
CVSS 4.0 vector shape for CVE-2026-41929Attack VectorAttack ComplexityAttack RequirementsPrivileges RequiredUser InteractionVS ConfidentialityVS IntegrityVS AvailabilitySS ConfidentialitySS IntegritySS Availability

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Attack Requirements
NonePresent
Privileges Required
NoneLowHigh
User Interaction
NonePassiveActive
VS Confidentiality
HighLowNone
VS Integrity
HighLowNone
VS Availability
HighLowNone
SS Confidentiality
HighLowNone
SS Integrity
HighLowNone
SS Availability
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
givanzVvveb0affected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-79 · source CWE mapping

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.