CVE-2025-9728

MEDIUM

Vvveb 1.0.7.2 - Cross-Site Scripting via Email/Password Argument

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-9728. PoCs published by helloandrewpaul.

AI-analyzed exploit summary This repository provides a detailed technical analysis of a reflected XSS vulnerability in Vvveb CMS v1.0.7.2, including root cause analysis, proof-of-concept payloads, and mitigation recommendations. The vulnerability allows script injection via the email and password fields due to lack of output encoding.

Description

A security vulnerability has been detected in givanz Vvveb 1.0.7.2. This affects an unknown part of the file app/template/user/login.tpl. Such manipulation of the argument Email/Password leads to cross site scripting. The attack can be executed remotely. The name of the patch is bbd4c42c66ab818142240348173a669d1d2537fe. Applying a patch is advised to resolve this issue.

Exploits (1)

nomisec WRITEUP
by helloandrewpaul · poc
https://github.com/helloandrewpaul/Reflected-XSS-in-Vvveb-CMS-v1.0.7.2

This repository provides a detailed technical analysis of a reflected XSS vulnerability in Vvveb CMS v1.0.7.2, including root cause analysis, proof-of-concept payloads, and mitigation recommendations. The vulnerability allows script injection via the email and password fields due to lack of output encoding.

Classification
Writeup 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Vvveb CMS v1.0.7.2
No auth needed
Prerequisites: Access to the login page of the vulnerable Vvveb CMS instance
MITRE ATT&CK
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.322017
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.322017
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.639704
Exploit, Issue Tracking, Third Party Advisory issue-tracking
https://github.com/givanz/Vvveb/issues/323

Scores

CVSS v3 4.3
EPSS 0.0035
EPSS Percentile 26.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-79 CWE-94
Status published
Products (1)
vvveb/vvveb 1.0.7.2
Published Aug 31, 2025
Tracked Since Feb 18, 2026