Vvveb
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 49 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 22, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Vvveb product question authorization bypass allows Vendors to read, approve, edit, or delete questions under other Vendors' products
Vvveb product authorization bypass allows Vendors to read, duplicate, or delete other Vendors' products
Vvveb post authorization bypass allows Authors to view, duplicate, or delete other Authors' posts
Vvveb comment authorization bypass allows Authors to read, approve, edit, or delete comments under other Authors' posts
Vvveb digital asset authorization bypass allows Vendors to list, read, edit, or delete other Vendors' digital assets
Vvveb: admin/auth-token IDOR allows unauthorized disclosure of administrator REST API tokens
Vvveb: Authenticated SQL injection in /user/orders via order_by and direction
Vvveb: Unauthenticated reflected XSS in public product return form via customer_order_id
Vvveb: Stored XSS in Posts allows privilege escalation via post editor
Vvveb: Vvveb CMS — Negative-quantity cart manipulation allows creation of orders with negative grand totals
Monitor Vvveb in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.