Vvveb
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 52 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 22, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Vvveb: Server-side request forgery in Vvveb via IPv6 bypass of validateUrl() in editor oEmbed proxy
Vvveb: Stored XSS in Vvveb via sanitizeHTML() filter bypass using a quoted greater-than character
Vvveb: Path traversal in Vvveb via sanitizeFileName() bypass enables arbitrary file read and delete through backup tools
Vvveb product question authorization bypass allows Vendors to read, approve, edit, or delete questions under other Vendors' products
Vvveb product authorization bypass allows Vendors to read, duplicate, or delete other Vendors' products
Vvveb post authorization bypass allows Authors to view, duplicate, or delete other Authors' posts
Vvveb comment authorization bypass allows Authors to read, approve, edit, or delete comments under other Authors' posts
Vvveb digital asset authorization bypass allows Vendors to list, read, edit, or delete other Vendors' digital assets
Vvveb: admin/auth-token IDOR allows unauthorized disclosure of administrator REST API tokens
Vvveb: Authenticated SQL injection in /user/orders via order_by and direction
Monitor Vvveb in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.