Vulnerabilities (CVE)

Filtered by vendor Vvveb Subscribe
Total 23 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-25183 1 Vvveb 1 Vvvebjs 2026-06-17 N/A 7.5 HIGH
givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php.
CVE-2024-25182 1 Vvveb 1 Vvvebjs 2026-06-17 N/A 9.8 CRITICAL
givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.
CVE-2024-25181 1 Vvveb 1 Vvvebjs 2026-06-17 N/A 9.1 CRITICAL
A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from improper handling of user-supplied URLs in the "file_get_contents" function within the "save.php" file.