CVE-2026-41933
Vvveb before 1.0.8.3 contains a directory listing information disclosure vulnerability that allows unauthenticated attackers to enumerate files and directories by accessing multiple paths lacking proper index directives in .htaccess files. Attackers can access directories such as admin asset paths, plugins, themes, and media folders to view filenames, file sizes, modification timestamps, and unrendered admin templates containing sensitive route maps.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.25%
- CWE
- CWE-548
- Published
- 2026-05-14
- Last modified
- 2026-07-28
Affected products
- givanz Vvveb
- givanz Vvveb
Weakness type
Related vulnerabilities
- CVE-2026-19987 — SourceCodester Best Employee Management System Profile exposure of information through directory listing
- CVE-2026-50233 — Lyrion Music Server 9.2.0 Arbitrary Directory Listing
- CVE-2025-32750 — Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory...
- CVE-2026-22860 — Rack has a Directory Traversal via Rack:Directory
- CVE-2023-38265 — Improper Access Control and Exposure of Information Through Directory Listing vulnerabilities affect IBM Cloud Pak System[, ]
- CVE-2020-36921 — RED-V Super Digital Signage System 5.1.1 Log Information Disclosure Vulnerability
- CVE-2022-50788 — SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Information Disclosure via Log Directory
- CVE-2021-47718 — OpenBMCS Directory Listing Information Disclosure