{"id":"CVE-2025-11029","title":"A weakness has been identified in givanz Vvveb up to 1.0.7.2","summary":"A weakness has been identified in givanz Vvveb up to 1.0.7.2. This vulnerability affects unknown code. Executing manipulation can lead to cross-site request forgery. The attack can be executed remotely. The exploit has been made availabl…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","cwe":["CWE-352","CWE-862","CWE-352"],"vendor":"vvveb","product":"vvveb","affected":["vvveb <= 1.0.7.2"],"published":"2025-09-26","updated":"2026-10-09","sourceUpdated":"2026-10-09T10:10:00.193","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-11029","references":[{"url":"https://gist.github.com/KhanMarshaI/165ae8f63ec6b5fdf1f4123252499fce","label":"cna@vuldb.com"},{"url":"https://gist.github.com/KhanMarshaI/db888b65cfd75bead2035348babfb423","label":"cna@vuldb.com"},{"url":"https://vuldb.com/?ctiid.325967","label":"cna@vuldb.com"},{"url":"https://vuldb.com/?id.325967","label":"cna@vuldb.com"},{"url":"https://vuldb.com/?submit.657188","label":"cna@vuldb.com"},{"url":"https://vuldb.com/?submit.657190","label":"cna@vuldb.com"},{"url":"https://vuldb.com/?submit.657191","label":"cna@vuldb.com"},{"url":"https://vuldb.com/?submit.657192","label":"cna@vuldb.com"},{"url":"https://gist.github.com/KhanMarshaI/165ae8f63ec6b5fdf1f4123252499fce","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://gist.github.com/KhanMarshaI/db888b65cfd75bead2035348babfb423","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.00284,"epssPercentile":0.1916,"ingestedAt":"2026-10-09T12:53:27.782Z","slug":"CVE-2025-11029","body":"## Overview\n\nA weakness has been identified in givanz Vvveb up to 1.0.7.2. This vulnerability affects unknown code. Executing manipulation can lead to cross-site request forgery. The attack can be executed remotely. The exploit has been made available to the public and could be exploited. Once again the project maintainer reacted very professional: \"I accept the existence of these vulnerabilities. (...) I fixed the code to remove these vulnerabilities and will push the code to github and make a new release.\"\n\n## Affected\n\n- `vvveb <= 1.0.7.2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}