SecAlerts
V

Vvveb

Security Risk Profile

59
/100
medium

Security Risk Score

Comprehensive risk assessment based on 49 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 22, 2024 to present

49
Total CVEs
28
Critical+High
0
Exploited
26
Unpatched

Threat Assessment

Avg CVSS
6.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
26
Critical/High
Risk Level
59/100
medium
🆕 5Fresh (<7d)📈 5 in Last 30 Days

Severity Distribution

Critical
8
High
20
Medium
15
Low
6

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
15

Age Distribution

Common Weaknesses (CWE)

1
XSS
12
2
Malicious File Upload
8
3
Code Injection
8
4
SQL Injection
7
5
SSRF
3

Most Affected Products

1. Vvveb vvveb34
2. givanz Vvveb14
3. Vvveb Vvveb CMS8
4. Vvveb Vvvebjs7
5. npm/vvvebjs2

Recent Vulnerabilities

See more →
CVE-2026-49222
CVSS 7.6high

Vvveb product question authorization bypass allows Vendors to read, approve, edit, or delete questions under other Vendors' products

Aug 18, 2026🔧 No Patch
CVE-2026-49228
CVSS 8.8high

Vvveb product authorization bypass allows Vendors to read, duplicate, or delete other Vendors' products

Aug 18, 2026🔧 No Patch
CVE-2026-49226
CVSS 8.3high

Vvveb post authorization bypass allows Authors to view, duplicate, or delete other Authors' posts

Aug 18, 2026🔧 No Patch
CVE-2026-49227
CVSS 7.6high

Vvveb comment authorization bypass allows Authors to read, approve, edit, or delete comments under other Authors' posts

Aug 18, 2026🔧 No Patch
CVE-2026-49221
CVSS 8.8high

Vvveb digital asset authorization bypass allows Vendors to list, read, edit, or delete other Vendors' digital assets

Aug 18, 2026🔧 No Patch
CVE-2026-46407
CVSS 8.1high

Vvveb: admin/auth-token IDOR allows unauthorized disclosure of administrator REST API tokens

May 15, 2026🔧 No Patch
CVE-2026-45800
CVSS 8.7high

Vvveb: Authenticated SQL injection in /user/orders via order_by and direction

May 15, 2026🔧 No Patch
CVE-2026-45622
CVSS 5.3medium

Vvveb: Unauthenticated reflected XSS in public product return form via customer_order_id

May 15, 2026🔧 No Patch
CVE-2026-45616
CVSS 5.1medium

Vvveb: Stored XSS in Posts allows privilege escalation via post editor

May 15, 2026🔧 No Patch
CVE-2026-44826
CVSS 7.5high

Vvveb: Vvveb CMS — Negative-quantity cart manipulation allows creation of orders with negative grand totals

May 15, 2026🔧 No Patch

Monitor Vvveb in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.