givanz
27 exploits
Active since Mar 2024
Vvveb < 1.0.8.3 Stored XSS via Signup Controller
CVSS 6.1
Vvveb < 1.0.8.3 Directory Listing Information Disclosure
CVSS 5.3
Vvveb < 1.0.8.3 Unrestricted File Upload RCE via Plugin Upload
CVSS 7.2
Vvveb < 1.0.8.2 Information Disclosure via Cron Controller
CVSS 5.3
Vvveb < 1.0.8.2 Unauthenticated Reflected XSS via Visual Editor
CVSS 6.1
Vvveb < 1.0.8.2 Hard-coded Credentials Information Disclosure via phpMyAdmin
CVSS 9.8
Vvveb < 1.0.8.2 Authenticated RCE via Code Editor
CVSS 8.8
Vvveb < 1.0.8.2 XML External Entity Injection via Import
CVSS 8.1
Vvveb < 1.0.8.2 RCE via Media Upload Handler
CVSS 8.8
givanz Vvveb <1.0.6.1 - Info Disclosure
CVSS 6.3
Vvveb 1.0.5 - Remote Code Execution in Code Editor Save Function
CVSS 4.7
Vvveb 1.0.7.2 - Cross-Site Scripting via Email/Password Argument
CVSS 4.3
Vvveb CMS 1.0.8 Remote Code Execution via Media Upload
CVSS 8.8
Vvveb CMS v1.0.8 Remote Code Execution via Media Management
CVSS 9.1
Vvveb < 1.0.8.1 Privilege Escalation via admin/user/save
CVSS 8.8
Vvveb < 1.0.8.1 SSRF via oEmbedProxy
CVSS 7.7
Vvveb < 1.0.8.1 Stored XSS via Media Upload and Rename
CVSS 5.4
Vvveb < 1.0.8.1 Code Injection via Installation Endpoint
CVSS 9.8
givanz Vvvebjs File Upload Endpoint upload.php cross site scripting
CVSS 4.3
vvvebjs < 1.7.7 - Reflected Cross-Site Scripting via save.php Action Parameter
CVSS 6.1
vvveb < 1.0.7.3 - SQL Injection via Import Function Raw SQL Handler
CVSS 4.7
vvveb < 1.0.7.3 - Path Traversal via File Argument in sanitizeFileName Function
CVSS 6.3
vvveb 1.0.6 - Remote Code Execution via Plugin Mechanism
CVSS 9.8
vvveb < 1.0.6 - Information Disclosure via Drag-and-Drop Editor URL Parameter
CVSS 2.7
vvveb < 1.0.6 - Server-Side Request Forgery via Drag-and-Drop Editor URL Parameter
CVSS 4.7