TROYANOSYVIRUS
Back to CVEs

CVE-2026-39918

CRITICAL
9.8

Description

Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parameter is written unsanitized into the env.php configuration file without escaping or validation. Attackers can inject arbitrary PHP code by breaking out of the string context in the define statement to achieve unauthenticated remote code execution as the web server user.

CVE Details

CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published4/20/2026
Last Modified4/20/2026
Sourcenvd
Honeypot Sightings0

Weaknesses (CWE)

CWE-94

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.