What is CVE-2026-49223?
CVE-2026-49223 is a vulnerability in Vvveb CMS before version 1.0.8.4, allowing a low-privileged Vendor to manage product reviews belonging to other Vendors via the `product_id` parameter in SQL queries. Vvveb CMS users should immediately update to the latest version.
Azərbaycanca: CVE-2026-49223 Vvveb CMS-in 1.0.8.4 versiyasından əvvəlki versiyalarında aşkar edilmiş boşluqdur. Bu boşluq aşağı səlahiyyətli Vendor istifadəçisinə, SQL sorğularında `product_id` parametri vasitəsilə başqa Vendor-un məhsul rəylərini idarə etməyə imkan verir. Vvveb CMS istifadəçiləri dərhal ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions of Vvveb CMS are affected by CVE-2026-49223?
This vulnerability exists in Vvveb CMS versions prior to 1.0.8.4.
Who can exploit the CVE-2026-49223 vulnerability?
This vulnerability allows a low-privileged Vendor to manage product reviews belonging to other Vendors via the `product_id` parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.