CVE-2025-8521: givanz Vvveb Add Type post-types cross site scripting
A vulnerability, which was classified as problematic, has been found in givanz Vvveb up to 1.0.5. This issue affects some unknown processing of the file /vadmin123/index.php?module=settings/post-types of the component Add Type Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.6 is able to address this issue. The patch is named b53c7161da606f512b7efcb392d6ffc708688d49/605a70f8729e4d44ebe272671cb1e43e3d6ae014. It is recommended to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
givanz Vvveb Add Type post-types cross site scriptingto a version that resolves this vulnerability.Fixed in 1.0.6Patch b53c7161da606f512b7efcb392d6ffc708688d49/605a70f8729e4d44ebe272671cb1e43e3d6ae014
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8521?
CVE-2025-8521 has been classified as a problematic vulnerability.
How do I fix CVE-2025-8521?
To fix CVE-2025-8521, it is recommended to update the Givanz Vvveb software to a version later than 1.0.5.
What type of vulnerability is CVE-2025-8521?
CVE-2025-8521 is a cross-site scripting (XSS) vulnerability.
Which versions of Givanz Vvveb are affected by CVE-2025-8521?
Givanz Vvveb versions up to and including 1.0.5 are affected by CVE-2025-8521.
What component is involved in CVE-2025-8521?
CVE-2025-8521 involves the Add Type Handler component, specifically in the file /vadmin123/index.php?module=settings/post-types.