VYPR

Vvvebjs

by Vvveb

Source repositories

CVEs (7)

  • CVE-2024-27480CriDec 29, 2025
    risk 0.64cvss 9.8epss 0.00

    givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.

  • CVE-2024-25182CriDec 29, 2025
    risk 0.64cvss 9.8epss 0.00

    givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.

  • CVE-2024-25181CriDec 29, 2025
    risk 0.59cvss 9.1epss 0.00

    A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from improper handling of user-supplied URLs in the "file_get_contents" function within the "save.php"…

  • CVE-2024-25183HigDec 29, 2025
    risk 0.49cvss 7.5epss 0.01

    givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php.

  • CVE-2024-29272MedMar 22, 2024
    risk 0.36cvss 6.5epss 0.09

    Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter in save.php.

  • CVE-2025-8522MedAug 4, 2025
    risk 0.33cvss 5.0epss 0.00

    A vulnerability, which was classified as critical, was found in givanz Vvvebjs up to 2.0.4. Affected is an unknown function of the file /save.php of the component node.js. The manipulation of the argument File leads to path traversal. It is possible to launch the attack…

  • CVE-2024-29271MedMar 22, 2024
    risk 0.33cvss 6.1epss 0.01

    Reflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.7, allows remote attackers to execute arbitrary code and obtain sensitive information via the action parameter in save.php.