CVE-2026-6249
HIGHVvveb CMS 1.0.8 Remote Code Execution via Media Upload
Title source: cnaDescription
Vvveb CMS 1.0.8 contains a remote code execution vulnerability in its media upload handler that allows authenticated attackers to execute arbitrary operating system commands by uploading a PHP webshell with a .phtml extension. Attackers can bypass the extension deny-list and upload malicious files to the publicly accessible media directory, then request the file over HTTP to achieve full server compromise.
Scores
CVSS v3
8.8
EPSS
0.0010
EPSS Percentile
26.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (1)
Vvveb/Vvveb CMS
1.0.8
Published
Apr 20, 2026
Tracked Since
Apr 21, 2026