Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 14 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vvveb before 1.0.8.3 contains a stored cross-site scripting vulnerability in the customer signup flow where the Signup::addUser() controller copies raw POST username values into the display_name field before sanitization occurs. Attackers can submit HTML and script markup in the username field during signup, which gets stripped from the username column but persisted verbatim in the display_name column, allowing stored XSS execution when display_name is rendered without encoding in vulnerable views. | |
| Title | Vvveb < 1.0.8.3 Stored XSS via Signup Controller | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-14T15:58:50.959Z
Reserved: 2026-04-22T18:50:43.620Z
Link: CVE-2026-41932
Updated: 2026-05-14T15:33:47.223Z
Status : Deferred
Published: 2026-05-14T15:16:45.730
Modified: 2026-05-14T16:24:56.240
Link: CVE-2026-41932
No data.
OpenCVE Enrichment
No data.