VYPR
Vendor

Vvveb

Products
2
CVEs
59
Across products
59
Status
Private

Products

2

Recent CVEs

59
View all 59 CVEs →
  • CVE-2024-27480CriDec 29, 2025
    risk 0.64cvss 9.8epss 0.00

    givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.

  • CVE-2024-25182CriDec 29, 2025
    risk 0.64cvss 9.8epss 0.00

    givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.

  • CVE-2024-25181CriDec 29, 2025
    risk 0.59cvss 9.1epss 0.00

    A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from improper handling of user-supplied URLs in the "file_get_contents" function within the "save.php"…

  • CVE-2026-41930CriMay 6, 2026
    risk 0.57cvss 9.8epss 0.01

    Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration that allows unauthenticated attackers to access the bundled phpMyAdmin container with pre-configured database credentials. Attackers can connect to the…

  • CVE-2026-39918CriApr 20, 2026
    risk 0.57cvss 9.8epss 0.01

    Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parameter is written unsanitized into the env.php configuration file without escaping or validation. Attackers can inject arbitrary PHP code by breaking out of the…

  • CVE-2026-6257CriApr 20, 2026
    risk 0.52cvss 9.1epss 0.01

    Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing return statement in the file rename handler allows authenticated attackers to rename files to blocked extensions .php or .htaccess. Attackers can exploit this…

  • CVE-2026-54612HigSep 17, 2026
    risk 0.50cvss 8.8epss 0.01

    Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until 1.0.8.5, saveGlobalElements() in admin/controller/editor/global-trait.php concatenates the attacker-controlled file portion of data-v-save-global to the…

  • CVE-2026-49228HigAug 18, 2026
    risk 0.50cvss 8.8epss 0.01

    Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product operations allow a low-privileged Vendor to access products owned by another Vendor. The admin/controller/product/products.php…

  • CVE-2026-49221HigAug 18, 2026
    risk 0.50cvss 8.8epss 0.01

    Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend digital asset operations allow a low-privileged Vendor to access digital assets linked to another Vendor's products. The…

  • CVE-2026-45800HigMay 15, 2026
    risk 0.50cvss —epss 0.00

    Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, there is an authenticated SQL injection issue in the frontend user order history page in Vvveb CMS. A normal frontend user can log in and access…

  • CVE-2026-41938HigMay 6, 2026
    risk 0.50cvss 8.8epss 0.01

    Vvveb before version 1.0.8.2 contains an unrestricted file upload vulnerability in the media upload handler that allows authenticated users with media-upload permissions to bypass extension restrictions by uploading a .htaccess file to map .phtml extensions to the PHP handler.…

  • CVE-2026-41934HigMay 6, 2026
    risk 0.50cvss 8.8epss 0.01

    Vvveb before version 1.0.8.2 contains an authenticated remote code execution vulnerability in the admin code editor that allows low-privilege authenticated users to execute arbitrary code through insufficient file extension restrictions, with the uploaded payload then executable…

  • CVE-2026-6249HigApr 20, 2026
    risk 0.50cvss 8.8epss 0.01

    Vvveb CMS 1.0.8.2 contains a remote code execution vulnerability in its media upload handler that allows authenticated attackers to execute arbitrary operating system commands by uploading a PHP webshell with a .phtml extension. Attackers can bypass the extension deny-list and…

  • CVE-2026-34427HigApr 20, 2026
    risk 0.50cvss 8.8epss 0.01

    Vvveb prior to 1.0.8.1 contains a privilege escalation vulnerability in the admin user profile save endpoint that allows authenticated users to modify privileged fields on their own profile. Attackers can inject role_id=1 into profile save requests to escalate to Super…

  • CVE-2024-25183HigDec 29, 2025
    risk 0.49cvss 7.5epss 0.01

    givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php.

  • CVE-2026-54507HigSep 17, 2026
    risk 0.48cvss —epss 0.00

    Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, the oEmbedProxy() handler in admin/controller/editor/editor.php accepts an attacker-controlled url parameter and passes it to getUrl(), while validateUrl()…

  • CVE-2026-49225HigAug 18, 2026
    risk 0.47cvss 8.3epss 0.00

    Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product revision operations allow a low-privileged Vendor to access revisions for products owned by another Vendor. The…

  • CVE-2026-49224HigAug 18, 2026
    risk 0.47cvss 8.3epss 0.00

    Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post revision operations allow a low-privileged Author to access revisions for posts owned by another Author. The…

  • CVE-2026-49226HigAug 18, 2026
    risk 0.47cvss 8.3epss 0.00

    Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post operations allow a low-privileged Author to access posts owned by another Author. The admin/controller/content/posts.php controller…

  • CVE-2026-46407HigMay 15, 2026
    risk 0.46cvss 8.1epss 0.00

    Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the backend admin/auth-token endpoint allows an authenticated administrator to load another administrator's REST API token list by supplying that user's…