SecAlerts
V

Vvveb

Security Risk Profile

59
/100
medium

Security Risk Score

Comprehensive risk assessment based on 52 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 22, 2024 to present

52
Total CVEs
31
Critical+High
0
Exploited
29
Unpatched

Threat Assessment

Avg CVSS
7
Base severity
Avg EPSS
1%
Exploit probability
Unpatched
29
Critical/High
Risk Level
59/100
medium
🆕 3Fresh (<7d)📈 3 in Last 30 Days

Severity Distribution

Critical
8
High
23
Medium
15
Low
6

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
1
<5%
14

Age Distribution

Common Weaknesses (CWE)

1
XSS
13
2
Malicious File Upload
8
3
Code Injection
8
4
SQL Injection
7
5
SSRF
4

Most Affected Products

1. Vvveb vvveb37
2. givanz Vvveb14
3. Vvveb Vvveb CMS8
4. Vvveb Vvvebjs7
5. npm/vvvebjs2

Recent Vulnerabilities

See more →
CVE-2026-55232
CVSS 7.6high

Vvveb: Server-side request forgery in Vvveb via IPv6 bypass of validateUrl() in editor oEmbed proxy

Oct 1, 2026🔧 No Patch
CVE-2026-55230
CVSS 8.7high

Vvveb: Stored XSS in Vvveb via sanitizeHTML() filter bypass using a quoted greater-than character

Oct 1, 2026🔧 No Patch
CVE-2026-55231
CVSS 7.2high

Vvveb: Path traversal in Vvveb via sanitizeFileName() bypass enables arbitrary file read and delete through backup tools

Oct 1, 2026🔧 No Patch
CVE-2026-49222
CVSS 7.6high

Vvveb product question authorization bypass allows Vendors to read, approve, edit, or delete questions under other Vendors' products

Aug 18, 2026🔧 No Patch
CVE-2026-49228
CVSS 8.8high

Vvveb product authorization bypass allows Vendors to read, duplicate, or delete other Vendors' products

Aug 18, 2026🔧 No Patch
CVE-2026-49226
CVSS 8.3high

Vvveb post authorization bypass allows Authors to view, duplicate, or delete other Authors' posts

Aug 18, 2026🔧 No Patch
CVE-2026-49227
CVSS 7.6high

Vvveb comment authorization bypass allows Authors to read, approve, edit, or delete comments under other Authors' posts

Aug 18, 2026🔧 No Patch
CVE-2026-49221
CVSS 8.8high

Vvveb digital asset authorization bypass allows Vendors to list, read, edit, or delete other Vendors' digital assets

Aug 18, 2026🔧 No Patch
CVE-2026-46407
CVSS 8.1high

Vvveb: admin/auth-token IDOR allows unauthorized disclosure of administrator REST API tokens

May 15, 2026🔧 No Patch
CVE-2026-45800
CVSS 8.7high

Vvveb: Authenticated SQL injection in /user/orders via order_by and direction

May 15, 2026🔧 No Patch

Monitor Vvveb in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

Vvveb Security Vulnerabilities & Risk Score | 52 CVEs | SecAlerts - SecAlerts