BRIEFING NOTE: CVE-2026-6249 Vvveb CMS version 1.0.8 contains a critical remote code execution vulnerability in its media upload handler that permits authenticated attackers to execute arbitrary operating system commands by uploading malicious PHP webshells with .phtml extensions, thereby bypassing file extension restrictions and achieving full server compromise. The vulnerability presents a high severity risk with a CVSS score of 8.8, requiring only low attack complexity and authenticated access over the network to exploit. The attack requires no user interaction and can result in complete compromise of system confidentiality, integrity, and availability through placement of executable files in publicly accessible media directories. This vulnerability is not currently listed on the Known Exploited Vulnerabilities catalog and shows minimal exploitation activity, with an EPSS score of 0.0009 indicating lower real-world exploitation probability. No public exploit code is currently documented, and community attention remains low, though the FAUCET risk score of 52.0 suggests continued monitoring is warranted for organizations running affected versions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Vvveb | Vvveb CMS | 1.0.8.2CNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.