Vvveb before 1.0.8.3 contains a directory listing information disclosure vulnerability that allows unauthenticated attackers to enumerate files and directories by accessing multiple paths lacking proper index directives in .htaccess files. Attackers can access directories such as admin asset paths, plugins, themes, and media folders to view filenames, file sizes, modification timestamps, and unrendered admin templates containing sensitive route maps.
References
Configurations
No configuration.
History
14 May 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-14 15:16
Updated : 2026-05-14 16:24
NVD link : CVE-2026-41933
Mitre link : CVE-2026-41933
CVE.ORG link : CVE-2026-41933
JSON object : View
Products Affected
No product.
CWE
CWE-548
Exposure of Information Through Directory Listing
