Known Vulnerabilities for Vvveb CMS by Vvveb
Listed below are 10 of the newest known vulnerabilities associated with "Vvveb CMS" by "Vvveb".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-41938 json | Vvveb before version 1.0.8.2 contains an unrestricted file upload vulnerability in the media upload handler that allows authe... | Not Provided | 2026-05-06 | 2026-05-06 |
| CVE-2026-41936 json | Vvveb before version 1.0.8.2 contains an XML external entity (XXE) injection vulnerability in the admin Tools/Import feature ... | Not Provided | 2026-05-06 | 2026-05-06 |
| CVE-2026-41934 json | Vvveb before version 1.0.8.2 contains an authenticated remote code execution vulnerability in the admin code editor that allo... | Not Provided | 2026-05-06 | 2026-05-06 |
| CVE-2026-41931 json | Vvveb before version 1.0.8.2 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain... | Not Provided | 2026-05-06 | 2026-05-06 |
| CVE-2026-41930 json | Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration ... | Not Provided | 2026-05-06 | 2026-05-06 |
| CVE-2026-41929 json | Vvveb before 1.0.8.2 contains an unauthenticated reflected cross-site scripting vulnerability in the visual editor preview re... | Not Provided | 2026-05-07 | 2026-05-08 |
| CVE-2026-41928 json | Vvveb before 1.0.8.2 contains an information disclosure vulnerability in the cron controller that allows unauthenticated atta... | Not Provided | 2026-05-07 | 2026-05-07 |
| CVE-2026-39918 json | Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parameter ... | Not Provided | 2026-04-20 | 2026-04-20 |
| CVE-2026-34429 json | Vvveb prior to 1.0.8.1 contains a stored cross-site scripting vulnerability that allows authenticated users with media uploa... | Not Provided | 2026-04-20 | 2026-05-07 |
| CVE-2026-34428 json | Vvveb prior to 1.0.8.1 contains a server-side request forgery vulnerability in the oEmbedProxy action of the editor/editor m... | Not Provided | 2026-04-20 | 2026-04-20 |