CVE-2025-8976: givanz Vvveb Endpoint post cross site scripting
A vulnerability has been found in givanz Vvveb up to 1.0.5. This vulnerability affects unknown code of the file /vadmin123/index.php?module=content/post&type=post of the component Endpoint. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.6 is able to address this issue. It is recommended to upgrade the affected component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8976?
CVE-2025-8976 has been classified as a medium severity vulnerability.
How do I fix CVE-2025-8976?
To fix CVE-2025-8976, upgrade the givanz Vvveb software to version 1.0.6 or later.
What type of vulnerability is CVE-2025-8976?
CVE-2025-8976 is a cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2025-8976?
CVE-2025-8976 affects users of givanz Vvveb versions up to 1.0.5.
Can CVE-2025-8976 be exploited remotely?
Yes, CVE-2025-8976 can be exploited remotely.