VendorsVvvebvvvebjsall versions
Vulnerabilities

Vvveb Vvvebjs

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2024-25182
givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.
Published 2025-12-29 · Modified
9.8EPSS 0.004
CVE-2024-27480
givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.
Published 2025-12-29 · Modified
9.8EPSS 0.004
CVE-2024-25181
A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from improper handling of user-supplied URLs in the "file_get_contents" function within the "save.php" file.
Published 2025-12-29 · Analyzed
9.1EPSS 0.003
CVE-2024-25183
givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php.
Published 2025-12-29 · Analyzed
7.5EPSS 0.007
CVE-2024-29272
Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter in save.php.
Published 2024-03-22 · Analyzed
6.5EPSS 0.094
CVE-2024-29271
Reflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.7, allows remote attackers to execute arbitrary code and obtain sensitive information via the action parameter in save.php.
Published 2024-03-22 · Analyzed
6.1EPSS 0.006
CVE-2025-8522
givanz Vvvebjs node.js save.php path traversal
Published 2025-08-04 · Analyzed
5.0EPSS 0.003