VulnSea

vvveb vulnerabilities

CVEs whose affected-version data names the vvveb package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

8 CVEsRSS

CVE-2026-55232High· 7.6PoC
1w ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's SSRF guard resolves a host with an IPv4-only function and never inspects IPv6, so any host that lac…

▾ Midnightgivanz · VvvebEPSS 0.32%via NVD
CVE-2026-55231High· 7.2PoC
1w ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, a flawed central path sanitizer lets an authenticated admin-panel user who holds backup access (default rol…

▾ Midnightgivanz · VvvebEPSS 0.52%via NVD
CVE-2026-55230High· 8.7PoC
1w ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's HTML sanitizer fails to strip event-handler attributes when a tag carries a greater-than character …

▾ Midnightgivanz · VvvebEPSS 0.32%via NVD
CVE-2026-54613Medium· 5.4PoC
3w ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, getThemeFolder() in admin/controller/editor/revisions.php returns the attacker-controlled theme parameter without s…

▾ Twilightgivanz · VvvebEPSS 0.34%via NVD
CVE-2026-54612High· 8.8
3w ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until 1.0.8.5, saveGlobalElements() in admin/controller/editor/global-trait.php concatenates the attacker-controlled file …

▾ Twilightgivanz · VvvebEPSS 0.76%via NVD
CVE-2026-54507High· 8.4
3w ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, the oEmbedProxy() handler in admin/controller/editor/editor.php accepts an attacker-controlled url parameter and pa…

▾ Twilightgivanz · VvvebEPSS 0.45%via NVD
CVE-2026-54506High· 7.6PoC
3w ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, app/controller/user/profile.php accepts the user[bio] field and passes stored content through sanitizeHTML() in sys…

▾ Midnightgivanz · VvvebEPSS 0.31%via NVD
CVE-2025-12203Medium· 6.3
11mo ago

A weakness has been identified in givanz Vvveb up to 1.0.7.3

A weakness has been identified in givanz Vvveb up to 1.0.7.3. This issue affects the function sanitizeFileName of the file system/functions.php of the component Code Editor. Executing a manipulation of the argument File can lead to path …

▾ Sunlitvvveb · vvvebEPSS 0.40%via NVD
vvveb vulnerabilities (CVEs) · VulnSea