Security: givanz/Vvveb
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Stored XSS via Comment Author FieldGHSA-gpmg-pcxr-9wvf published
May 4, 2026 by givanzModerate -
Authenticated XXE in `tools/import` Reaches Site_admin → Arbitrary File Read + Lateral Move to Super_adminGHSA-rfxr-4xpm-wrp7 published
May 4, 2026 by givanzCritical -
Authenticated RCE via `editor/code/save` `.htaccess` Override (Editor / Author / Contributor / Site_admin)GHSA-vfjj-gcvv-w248 published
May 4, 2026 by givanzCritical -
Pre-authentication PHP Stack-Trace and Source-Code Disclosure via DEBUG=trueGHSA-xgvg-r47g-786r published
May 4, 2026 by givanzHigh -
Unauthenticated phpMyAdmin (auth_type=config) Yields Full Database Read/Write and Bcrypt Hash DumpGHSA-g38h-mr9p-fjmf published
May 4, 2026 by givanzCritical -
Unauthenticated Reflected Cross-Site Scripting via Editor Preview BypassGHSA-wwmv-4g9g-p48g published
May 4, 2026 by givanzCritical -
Unauthenticated Remo te Code Execution via .phtml + .htaccess Upload (Apache Deployments)GHSA-qpcx-gx2x-r8v2 published
May 4, 2026 by givanzCritical -
Stored Cross-Site Scripting via HTML File Upload BypassGHSA-2vc4-49hq-g7f4 published
Apr 29, 2026 by givanzHigh -
Vvveb CMS — Negative-quantity cart manipulation allows creation of orders with negative grand totalsGHSA-75x2-j47j-mg8j published
May 4, 2026 by givanzHigh -
Privilege Escalation to Super Administrator via Profile Save FormGHSA-5m79-v4p3-gh3f published
Apr 29, 2026 by givanzCritical
Learn more about advisories related to givanz/Vvveb in the GitHub Advisory Database