vciy

CVEs we hold for Givanz

Records whose assigning authority named Givanz as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-5615givanz Vvvebjs File Upload Endpoint upload.php cross site scriptinggivanz Vvvebjs
CVE-2026-54613Vvveb: Path Traversal in Revision Backup Reader/Deleter via Unsanitized theme Parametergivanz Vvveb
CVE-2026-54612Vvveb: Authenticated editor path traversal to PHP file write/RCE via data-v-save-globalgivanz Vvveb
CVE-2026-54507Vvveb oEmbedProxy vulnerable to server-side request forgerygivanz Vvveb
CVE-2026-54506Vvveb: Stored XSS via sanitizeHTML() bypass in user profile bio fieldgivanz Vvveb
CVE-2026-49228Vvveb product authorization bypass allows Vendors to read, duplicate, or delete other Vendors' productsgivanz Vvveb
CVE-2026-49227Vvveb comment authorization bypass allows Authors to read, approve, edit, or delete comments under other Authors' postsgivanz Vvveb
CVE-2026-49226Vvveb post authorization bypass allows Authors to view, duplicate, or delete other Authors' postsgivanz Vvveb
CVE-2026-49225Vvveb product revision authorization bypass allows Vendors to read, restore, or delete other Vendors' product revisionsgivanz Vvveb
CVE-2026-49224Vvveb post revision authorization bypass allows Authors to read, restore, or delete other Authors' post revisionsgivanz Vvveb
CVE-2026-49223Vvveb product review authorization bypass allows Vendors to read, approve, edit, or delete reviews under other Vendors'…givanz Vvveb
CVE-2026-49222Vvveb product question authorization bypass allows Vendors to read, approve, edit, or delete questions under other…givanz Vvveb
CVE-2026-49221Vvveb digital asset authorization bypass allows Vendors to list, read, edit, or delete other Vendors' digital assetsgivanz Vvveb
CVE-2026-46408Vvveb: checkout IDOR allows unauthorized reuse of another user's cartgivanz Vvveb
CVE-2026-46407Vvveb: admin/auth-token IDOR allows unauthorized disclosure of administrator REST API tokensgivanz Vvveb
CVE-2026-45800Vvveb: Authenticated SQL injection in /user/orders via order_by and directiongivanz Vvveb
CVE-2026-45622Vvveb: Unauthenticated reflected XSS in public product return form via customer_order_idgivanz Vvveb
CVE-2026-45616Vvveb: Stored XSS in Posts allows privilege escalation via post editorgivanz Vvveb
CVE-2026-44826Vvveb: Vvveb CMS — Negative-quantity cart manipulation allows creation of orders with negative grand totalsgivanz Vvveb
CVE-2026-44366Vvveb: Stored XSS via Comment Author Fieldgivanz Vvveb
CVE-2026-41938Vvveb < 1.0.8.2 RCE via Media Upload Handlergivanz Vvveb
CVE-2026-41937Vvveb < 1.0.8.3 Unrestricted File Upload RCE via Plugin Uploadgivanz Vvveb
CVE-2026-41936Vvveb < 1.0.8.2 XML External Entity Injection via Importgivanz Vvveb
CVE-2026-41935Vvveb < 1.0.8.3 Uncontrolled Recursion Denial of Servicegivanz Vvveb
CVE-2026-41934Vvveb < 1.0.8.2 Authenticated RCE via Code Editorgivanz Vvveb
CVE-2026-41933Vvveb < 1.0.8.3 Directory Listing Information Disclosuregivanz Vvveb
CVE-2026-41932Vvveb < 1.0.8.3 Stored XSS via Signup Controllergivanz Vvveb
CVE-2026-41931Vvveb < 1.0.8.2 Information Disclosure via Debug Exception Handlergivanz Vvveb
CVE-2026-41930Vvveb < 1.0.8.2 Hard-coded Credentials Information Disclosure via phpMyAdmingivanz Vvveb
CVE-2026-41929Vvveb < 1.0.8.2 Unauthenticated Reflected XSS via Visual Editorgivanz Vvveb
CVE-2026-41928Vvveb < 1.0.8.2 Information Disclosure via Cron Controllergivanz Vvveb
CVE-2026-39918Vvveb < 1.0.8.1 Code Injection via Installation Endpointgivanz Vvveb
CVE-2026-34429Vvveb < 1.0.8.1 Stored XSS via Media Upload and Renamegivanz Vvveb
CVE-2026-34428Vvveb < 1.0.8.1 SSRF via oEmbedProxygivanz Vvveb
CVE-2026-34427Vvveb < 1.0.8.1 Privilege Escalation via admin/user/savegivanz Vvveb
CVE-2025-9728givanz Vvveb login.tpl cross site scriptinggivanz Vvveb
CVE-2025-9397givanz Vvveb media.php unrestricted uploadgivanz Vvveb
CVE-2025-8976givanz Vvveb Endpoint post cross site scriptinggivanz Vvveb
CVE-2025-8975givanz Vvveb edit.tpl cross site scriptinggivanz Vvveb
CVE-2025-8522givanz Vvvebjs node.js save.php path traversalgivanz Vvvebjs
CVE-2025-8521givanz Vvveb Add Type post-types cross site scriptinggivanz Vvveb
CVE-2025-8520givanz Vvveb Drag-and-Drop Editor editor server-side request forgerygivanz Vvveb
CVE-2025-8519givanz Vvveb Drag-and-Drop Editor editor information disclosuregivanz Vvveb
CVE-2025-8518givanz Vvveb Code Editor code.php save code injectiongivanz Vvveb
CVE-2025-8517givanz Vvveb session fixiationgivanz Vvveb
CVE-2025-12203givanz Vvveb Code Editor functions.php sanitizeFileName path traversalgivanz Vvveb
CVE-2025-11944givanz Vvveb Raw SQL import.php import sql injectiongivanz Vvveb
CVE-2025-11029givanz Vvveb cross-site request forgerygivanz Vvveb
CVE-2025-11028givanz Vvveb Image information disclosuregivanz Vvveb
CVE-2025-11027givanz Vvveb SVG File cross site scriptinggivanz Vvveb
CVE-2025-11026givanz Vvveb Configuration File information disclosuregivanz Vvveb

51 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.