CVE-2026-41929Disclosure

LOWCVSS 5.1 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Vvveb before 1.0.8.2 contains an unauthenticated reflected cross-site scripting vulnerability in the visual editor preview renderer that allows attackers to execute arbitrary JavaScript by manipulating the r query parameter and _component_ajax POST parameter. Attackers can craft a malicious link or auto-submitted form that causes victims to execute attacker-controlled JavaScript in the context of the Vvveb origin, as the gating function isEditor() performs no session, role, or token verification and the view handler injects raw HTML POST body content without sanitization.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-08); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-08: 1Mentions · 2026-05-10: 1PoC Mentioned / Linked · 2026-05-08: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-10: 105-0805-10
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-41929 Vvveb before 1.0.8.2 contains an unauthenticated reflected cross-site scripting vulnerability in the visual editor preview renderer that allows attackers to execute a… https://www.cve.org/CVERecord?id=CVE-2026-41929

    Post summary

    The tweet announces the discovery of an unauthenticated reflected XSS vulnerability in Vvveb CMS (v<1.0.8.2) that could enable attacker‑executed scripts.

    00000214
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41929 Unauthenticated Reflected Cross-Site Scripting in Vvveb Before 1.0.8.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41929

    Post summary

    The entry announces CVE‑2026‑41929 as an unauthenticated reflected XSS vulnerability affecting Vvveb prior to version 1.0.8.2, with a link to further technical details.

    0000068
    4.0K followersView on X

Explore more