Skip to content

Vvveb CMS

v1.0.8.5 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

backend blog blog-engine blog-platform blogging cms
+14 more
content-management content-management-system ecommerce ecommerce-platform no-code page-builder php php-cms php7 php8 self-hosted shopping-cart web website-builder

Affected surfaces

auth rbac

ReleasePort's take

Moderate signal
editorial:auto 1mo

Version 1.0.8.5 removes the editor/* permission for the editor role and adds input‑sanitization fixes.

Why it matters: Removal of editor/* triggers configuration migration; sanitization patches block XSS with severity 90.

Summary

AI summary

Removed the editor/* permission for the editor role, requiring migration of role configurations.

Changes in this release

Security Critical

Sanitize save global file, removed editor/* permission for editor role

Sanitize save global file, removed editor/* permission for editor role

Source: llm_adapter@2026-06-07

Confidence: high

Security Critical

Sanitize theme name to prevent injection attacks

Sanitize theme name to prevent injection attacks

Source: llm_adapter@2026-06-07

Confidence: high

Security Critical

Added sanitize to user bio on profile save; fixed sanitizeHTML to block XSS variants

Added sanitize to user bio on profile save; fixed sanitizeHTML to block XSS variants

Source: llm_adapter@2026-06-07

Confidence: high

Feature Low

Introduced field templates for easier form creation

Introduced field templates for easier form creation

Source: llm_adapter@2026-06-07

Confidence: high

Bugfix Medium

Validate URL by checking host IP address to avoid private‑network redirects

Validate URL by checking host IP address to avoid private‑network redirects

Source: llm_adapter@2026-06-07

Confidence: low

Full changelog
  • Sanitize save global file, removed editor/* permission for editor role, reported by @m1n9yu3 https://github.com/givanz/Vvveb/commit/c8fef41ad8651d348050c513451755ab8882b97e
  • Sanitize theme name, reported by @geo-chen https://github.com/givanz/Vvveb/commit/1d76ad52402beeed623a7e386c6796126689a746
  • Added sanitize to user bio on profile save, fixed sanitizeHTML to prevent more XSS variants, reported by @JosanGeorge https://github.com/givanz/Vvveb/commit/20a01ef08559ffdc97205edeecde86c8ea27e567
  • Check host ip address for validateUrl to avoid ip redirects to private network, reported by @elvinsuleymanov https://github.com/givanz/Vvveb/commit/bd280f5ce136f6da22c873fb1eea9cad8741e623
  • Field templates https://github.com/givanz/Vvveb/commit/57a342b8c96872e084fef7931783243dc74438b1

Breaking Changes

  • Removed editor/* permission for the editor role

Security Fixes

  • Fixed sanitizeHTML to prevent additional XSS variants

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Vvveb CMS

Get notified when new releases ship.

Sign up free

About Vvveb CMS

Powerful and easy to use CMS to build websites, blogs or e-commerce stores.

All releases →

Related context

Earlier breaking changes

  • v1.0.8.4 Removes subdir from request URI for subdir installs

Beta — feedback welcome: [email protected]