{"id":"CVE-2026-54506","summary":"Vvveb: Stored XSS via sanitizeHTML() bypass in user profile bio field","details":"Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, app/controller/user/profile.php accepts the user[bio] field and passes stored content through sanitizeHTML() in system/functions.php, whose on* event-handler regular expression omits the forward-slash delimiter and whose do-while condition compares the string to itself, so forbidden nested tags are removed only once. An Author-role or higher user can submit solidus-prefixed event-handler markup or nested forbidden tags that survive sanitization. The stored bio is rendered without sufficient output encoding on /author/{username}, in the admin user-management view, and potentially in comment displays, causing attacker-controlled JavaScript to execute when unauthenticated visitors, administrators, or other users view the content. This can expose browser-session data and permit victim-context account actions, defacement, or phishing. This issue is fixed in version 1.0.8.5.","aliases":["GHSA-5cg7-phhv-4qjr"],"modified":"2026-09-25T03:30:33.218558102Z","published":"2026-09-17T21:47:20.530Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-116","CWE-185","CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54506.json"},"references":[{"type":"WEB","url":"https://github.com/givanz/Vvveb/releases/tag/1.0.8.5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54506.json"},{"type":"ADVISORY","url":"https://github.com/givanz/Vvveb/security/advisories/GHSA-5cg7-phhv-4qjr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54506"},{"type":"FIX","url":"https://github.com/givanz/Vvveb/commit/20a01ef08559ffdc97205edeecde86c8ea27e567"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/givanz/vvveb","events":[{"introduced":"0"},{"fixed":"20a01ef08559ffdc97205edeecde86c8ea27e567"},{"fixed":"c8fef41ad8651d348050c513451755ab8882b97e"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"1.0.8.5"}]}}],"versions":["1.0.8.4","1.0.8.3","1.0.8.2","1.0.8.1","1.0.8","1.0.7.3","1.0.7.2","1.0.7.1","1.0.7","1.0.6","1.0.5","1.0.4","1.0.3","1.0.2","1.0.1","1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54506.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N"}]}