Vulnerabilities
23 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-27480 | givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload. givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2025-12203 | A weakness has been identified in givanz Vvveb up to 1.0.7.3. A weakness has been identified in givanz Vvveb up to 1.0.7.3. This issue affects the function sanitizeFileName of the file system/functions.php of the component Code Editor. Executing a manipulation of the argument File can lead to path traversal. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. This patch is called b0fa7ff74a3539c6d37000db152caad572e4c39b. Applying a patch is advised to resolve this issue. NVD description · AI analysis pending | 2.1 | <1% | PoC |
| — | |
| CVE-2025-11944 | A vulnerability was determined in givanz Vvveb up to 1.0.7.3. A vulnerability was determined in givanz Vvveb up to 1.0.7.3. This affects the function Import of the file admin/controller/tools/import.php of the component Raw SQL Handler. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: 52204b4a106b2fb02d16eee06a88a1f2697f9b35. It is recommended to apply a patch to fix this issue. NVD description · AI analysis pending | 2.0 | <1% | PoC ×2 |
| — | |
| CVE-2025-11028 | A security flaw has been discovered in givanz Vvveb up to 1.0.7.2. A security flaw has been discovered in givanz Vvveb up to 1.0.7.2. This affects an unknown part of the component Image Handler. Performing manipulation results in information disclosure. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited. Once again the project maintainer reacted very professional: "I accept the existence of these vulnerabilities. (...) I fixed the code to remove these vulnerabilities and will push the code to github and make a new release." NVD description · AI analysis pending | 5.5 group max | <1% | PoC |
| — | |
| CVE-2025-9728 | A security vulnerability has been detected in givanz Vvveb 1.0.7.2. A security vulnerability has been detected in givanz Vvveb 1.0.7.2. This affects an unknown part of the file app/template/user/login.tpl. Such manipulation of the argument Email/Password leads to cross site scripting. The attack can be executed remotely. The name of the patch is bbd4c42c66ab818142240348173a669d1d2537fe. Applying a patch is advised to resolve this issue. NVD description · AI analysis pending | 5.3 | <1% | PoC ×2 |
| — | |
| CVE-2025-9397 | A weakness has been identified in givanz Vvveb up to 1.0.7.2. A weakness has been identified in givanz Vvveb up to 1.0.7.2. Affected is an unknown function of the file /system/traits/media.php. Executing manipulation of the argument files[] can lead to unrestricted upload. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. Applying a patch is advised to resolve this issue. The code maintainer explains, that "[he] fixed the code to remove this vulnerability and will make a new release". NVD description · AI analysis pending | 2.1 | <1% | PoC ×2 |
| — | |
| CVE-2025-8975 +1 in the same advisory: …8976 | A vulnerability was identified in givanz Vvveb up to 1.0.5. A vulnerability was identified in givanz Vvveb up to 1.0.5. This affects an unknown part of the file admin/template/content/edit.tpl. The manipulation of the argument slug leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.6 is able to address this issue. The patch is named 84c11d69df8452dc378feecd17e2a62ac10dac66. It is recommended to upgrade the affected component. NVD description · AI analysis pending | 2.0 | <1% | PoC |
| — | |
| CVE-2025-8522 | A vulnerability, which was classified as critical, was found in givanz Vvvebjs up to 2.0.4. A vulnerability, which was classified as critical, was found in givanz Vvvebjs up to 2.0.4. Affected is an unknown function of the file /save.php of the component node.js. The manipulation of the argument File leads to path traversal. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 1.3 | <1% | PoC ×2 |
| — | |
| CVE-2025-8517 | A vulnerability was detected in givanz Vvveb 1.0.6.1. A vulnerability was detected in givanz Vvveb 1.0.6.1. Impacted is an unknown function. The manipulation results in session fixiation. The attack can be launched remotely. The exploit is now public and may be used. Upgrading to version 1.0.7 is recommended to address this issue. The patch is identified as d4b1e030066417b77d15b4ac505eed5ae7bf2c5e. You should upgrade the affected component. NVD description · AI analysis pending | 2.1 group max | <1% | PoC ×3 |
| — | |
| CVE-2025-44022 | An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin mechanism. An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin mechanism. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2024-29272 +1 in the same advisory: …29271 | Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive info Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter in save.php. NVD description · AI analysis pending | 6.5 group max | 9% | PoC |
| — |