CVE-2024-25182

givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:vvveb:vvvebjs:1.7.2:*:*:*:*:*:*:*

History

02 Jan 2026, 14:05

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Vvveb vvvebjs
Vvveb
References () https://gist.github.com/joaoviictorti/ff6220d8ed6df77a0420f4413a1d9b8d - () https://gist.github.com/joaoviictorti/ff6220d8ed6df77a0420f4413a1d9b8d - Exploit, Issue Tracking
CPE cpe:2.3:a:vvveb:vvvebjs:1.7.2:*:*:*:*:*:*:*
CWE CWE-434

29 Dec 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-29 21:15

Updated : 2026-01-02 22:15


NVD link : CVE-2024-25182

Mitre link : CVE-2024-25182

CVE.ORG link : CVE-2024-25182


JSON object : View

Products Affected

vvveb

  • vvvebjs
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type