vulns.co
/
GKData.io MCP

Vvveb · 1 min read

Vvveb: numeric input validity does not establish legitimate order state

CVE-2026-44826 concerns missing domain constraints between cart quantities and authoritative orders. Arithmetic propagated invalid purchase state through totals and checkout. The maintainer-published report describes a validated run producing a persisted negative-total order, distinguishing a durable integrity failure from an incorrect display.

Open the reference Maintainer AdvisoryReviewed 2026-10-04

How to use this reference

Editorial reasoning: trace domain invariants across every transition that makes provisional state authoritative. Require valid quantities during cart mutation and revalidate order constraints at commitment. Keep legitimate credit workflows distinct from purchases. The advisory proposes these checks; release 1.0.8.2 explicitly lists the corresponding repair.

Before reading

  • Basic understanding of checkout state, numeric validation and database integrity

Context and limits

  • The advisory lists versions through 1.0.8 as affected and 1.0.8.2 as patched; it does not explicitly classify intervening 1.0.8.1.
  • The reported setting permits guest checkout without special extensions. External accounting, inventory or payment consequences depend on integration behavior; actual payouts or production losses are not demonstrated.
  • The release page displays May 4 without a year in the retrieved rendering. No full software-release date is asserted, and patch version is not an educational edition.
  • The advisory is published by the givanz account. Its Discoverer Credit section names Basant Kumar as primary discoverer and Hamed Kohi as co-discoverer; these roles do not establish advisory authorship, so named authors remain unestablished. Original analysis here is limited to defensive design lessons.

Sources and provenance

  1. Vvveb CMS — Negative-quantity cart manipulation allows creation of orders with negative grand totals Vvveb · reviewed 2026-10-04
  2. Vvveb 1.0.8.2 Vvveb · reviewed 2026-10-04

Record reviewed 2026-10-04. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software