What is CVE-2026-49225?
CVE-2026-49225 is a vulnerability in Vvveb CMS where low-privileged Vendor users can access product revisions belonging to other Vendors due to a flaw in the admin/controller/product/revisions.php route. This affects versions prior to 1.0.8.4, and upgrading is strongly recommended.
Azərbaycanca: CVE-2026-49225 Vvveb CMS-də aşağı səlahiyyətli Vendor istifadəçilərinə başqa Vendor-lara məxsus məhsul reviziyalarına icazəsiz giriş imkanı verən zəiflikdir. Bu, admin/controller/product/revisions.php faylındakı nöqsan səbəbindən baş verir. 1.0.8.4 versiyasından əvvəlki quraşdırmalar təsirlənir və təcili yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which privileged users are affected by CVE-2026-49225 in Vvveb CMS?
This vulnerability affects low-privileged Vendor users.
Which versions of Vvveb CMS are vulnerable to CVE-2026-49225?
Installations prior to version 1.0.8.4 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.