CVEs we hold for Givanz
Records whose assigning authority named Givanz as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-5615givanz Vvvebjs File Upload Endpoint upload.php cross site scriptinggivanz Vvvebjs CVE-2026-54613Vvveb: Path Traversal in Revision Backup Reader/Deleter via Unsanitized theme Parametergivanz Vvveb CVE-2026-54612Vvveb: Authenticated editor path traversal to PHP file write/RCE via data-v-save-globalgivanz Vvveb CVE-2026-54507Vvveb oEmbedProxy vulnerable to server-side request forgerygivanz Vvveb CVE-2026-54506Vvveb: Stored XSS via sanitizeHTML() bypass in user profile bio fieldgivanz Vvveb CVE-2026-49228Vvveb product authorization bypass allows Vendors to read, duplicate, or delete other Vendors' productsgivanz Vvveb CVE-2026-49227Vvveb comment authorization bypass allows Authors to read, approve, edit, or delete comments under other Authors' postsgivanz Vvveb CVE-2026-49226Vvveb post authorization bypass allows Authors to view, duplicate, or delete other Authors' postsgivanz Vvveb CVE-2026-49225Vvveb product revision authorization bypass allows Vendors to read, restore, or delete other Vendors' product revisionsgivanz Vvveb CVE-2026-49224Vvveb post revision authorization bypass allows Authors to read, restore, or delete other Authors' post revisionsgivanz Vvveb CVE-2026-49223Vvveb product review authorization bypass allows Vendors to read, approve, edit, or delete reviews under other Vendors'…givanz Vvveb CVE-2026-49222Vvveb product question authorization bypass allows Vendors to read, approve, edit, or delete questions under other…givanz Vvveb CVE-2026-49221Vvveb digital asset authorization bypass allows Vendors to list, read, edit, or delete other Vendors' digital assetsgivanz Vvveb CVE-2026-46408Vvveb: checkout IDOR allows unauthorized reuse of another user's cartgivanz Vvveb CVE-2026-46407Vvveb: admin/auth-token IDOR allows unauthorized disclosure of administrator REST API tokensgivanz Vvveb CVE-2026-45800Vvveb: Authenticated SQL injection in /user/orders via order_by and directiongivanz Vvveb CVE-2026-45622Vvveb: Unauthenticated reflected XSS in public product return form via customer_order_idgivanz Vvveb CVE-2026-45616Vvveb: Stored XSS in Posts allows privilege escalation via post editorgivanz Vvveb CVE-2026-44826Vvveb: Vvveb CMS — Negative-quantity cart manipulation allows creation of orders with negative grand totalsgivanz Vvveb CVE-2026-41938Vvveb < 1.0.8.2 RCE via Media Upload Handlergivanz Vvveb CVE-2026-41937Vvveb < 1.0.8.3 Unrestricted File Upload RCE via Plugin Uploadgivanz Vvveb CVE-2026-41936Vvveb < 1.0.8.2 XML External Entity Injection via Importgivanz Vvveb CVE-2026-41935Vvveb < 1.0.8.3 Uncontrolled Recursion Denial of Servicegivanz Vvveb CVE-2026-41934Vvveb < 1.0.8.2 Authenticated RCE via Code Editorgivanz Vvveb CVE-2026-41933Vvveb < 1.0.8.3 Directory Listing Information Disclosuregivanz Vvveb CVE-2026-41932Vvveb < 1.0.8.3 Stored XSS via Signup Controllergivanz Vvveb CVE-2026-41931Vvveb < 1.0.8.2 Information Disclosure via Debug Exception Handlergivanz Vvveb CVE-2026-41930Vvveb < 1.0.8.2 Hard-coded Credentials Information Disclosure via phpMyAdmingivanz Vvveb CVE-2026-41929Vvveb < 1.0.8.2 Unauthenticated Reflected XSS via Visual Editorgivanz Vvveb CVE-2026-41928Vvveb < 1.0.8.2 Information Disclosure via Cron Controllergivanz Vvveb CVE-2026-39918Vvveb < 1.0.8.1 Code Injection via Installation Endpointgivanz Vvveb CVE-2026-34429Vvveb < 1.0.8.1 Stored XSS via Media Upload and Renamegivanz Vvveb CVE-2026-34427Vvveb < 1.0.8.1 Privilege Escalation via admin/user/savegivanz Vvveb CVE-2025-9728givanz Vvveb login.tpl cross site scriptinggivanz Vvveb CVE-2025-9397givanz Vvveb media.php unrestricted uploadgivanz Vvveb CVE-2025-8976givanz Vvveb Endpoint post cross site scriptinggivanz Vvveb CVE-2025-8975givanz Vvveb edit.tpl cross site scriptinggivanz Vvveb CVE-2025-8522givanz Vvvebjs node.js save.php path traversalgivanz Vvvebjs CVE-2025-8521givanz Vvveb Add Type post-types cross site scriptinggivanz Vvveb CVE-2025-8520givanz Vvveb Drag-and-Drop Editor editor server-side request forgerygivanz Vvveb CVE-2025-8519givanz Vvveb Drag-and-Drop Editor editor information disclosuregivanz Vvveb CVE-2025-8518givanz Vvveb Code Editor code.php save code injectiongivanz Vvveb CVE-2025-12203givanz Vvveb Code Editor functions.php sanitizeFileName path traversalgivanz Vvveb CVE-2025-11944givanz Vvveb Raw SQL import.php import sql injectiongivanz Vvveb CVE-2025-11026givanz Vvveb Configuration File information disclosuregivanz Vvveb 51 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.