Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6249

28
FAUCET Score

BRIEFING NOTE: CVE-2026-6249 Vvveb CMS version 1.0.8 contains a critical remote code execution vulnerability in its media upload handler that permits authenticated attackers to execute arbitrary operating system commands by uploading malicious PHP webshells with .phtml extensions, thereby bypassing file extension restrictions and achieving full server compromise. The vulnerability presents a high severity risk with a CVSS score of 8.8, requiring only low attack complexity and authenticated access over the network to exploit. The attack requires no user interaction and can result in complete compromise of system confidentiality, integrity, and availability through placement of executable files in publicly accessible media directories. This vulnerability is not currently listed on the Known Exploited Vulnerabilities catalog and shows minimal exploitation activity, with an EPSS score of 0.0009 indicating lower real-world exploitation probability. No public exploit code is currently documented, and community attention remains low, though the FAUCET risk score of 52.0 suggests continued monitoring is warranted for organizations running affected versions.

Impacted Technologies

VendorProductVersion(s)CPE
VvvebVvveb CMS
1.0.8.2CNA affecteddefault affected

CVSS Data

CVSS version used by this source: 4.0

8.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.62%
Probability of exploitation in next 30 days
EPSS Percentile
46.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0062 is in the 37th percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / givanz/Vvveb/commit/23ac0e8c758d80f3c4d9224763c8b2359648270e
vulncheck.com / advisories/vvveb-cms-remote-code-execution-via-media-upload