Vvveb is a page-builder and website-creation platform with a focused but strategically positioned product line that includes its core builder and JavaScript components, placing it among more-prominent vendors in the vulnerability landscape despite a small overall portfolio. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency toward public exploit availability, consistent with the web-application and code-execution risks inherent to builder platforms. The exposure concentrates in the Vvveb builder and VvvebJS products and recurs through weakness classes including code injection, cross-site scripting, improper access control, unrestricted file uploads, and exposure of sensitive information—a pattern characteristic of platforms that handle user-supplied content and dynamic code generation. Defenders should treat builder-platform patches as high-priority given the downstream effect on generated websites and user data handling; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vvveb over time
Signals from CVEs in this vendor scope (38 CVEs).
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8518HIGH A vulnerability was found in givanz Vvveb 1.0.5. It has been rated as critical. Affected by this issue is the function Save of the file admin/controller/editor/code.php of the comp | Aug 4, 2025 | 7.2 | 40 | NO | YES |
CVE-2026-41930CRITICAL Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration that allows unauthenticated attackers to access the bun | May 6, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-39918CRITICAL Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parameter is written unsanitized into the env.php configuration fi | Apr 20, 2026 | 9.8 | 37 | NO | NO |
CVE-2024-25182CRITICAL givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php. | Dec 29, 2025 | 9.8 | 34 | NO | NO |
CVE-2024-25181CRITICAL A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from | Dec 29, 2025 | 9.1 | 33 | NO | NO |
CVE-2024-29272MEDIUM Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sani | Mar 22, 2024 | 6.5 | 33 | NO | YES |
CVE-2026-34427HIGH Vvveb prior to 1.0.8.1 contains a privilege escalation vulnerability in the admin user profile save endpoint that allows authenticated users to modify privileged fields on their ow | Apr 20, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-41938HIGH Vvveb before version 1.0.8.2 contains an unrestricted file upload vulnerability in the media upload handler that allows authenticated users with media-upload permissions to bypass | May 6, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-41934HIGH Vvveb before version 1.0.8.2 contains an authenticated remote code execution vulnerability in the admin code editor that allows low-privilege authenticated users to execute arbitra | May 6, 2026 | 8.8 | 31 | NO | NO |
CVE-2024-27480CRITICAL givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload. | Dec 29, 2025 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (38 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vvveb.
Media articles that mention a CVE ID that affects a product developed by Vvveb — matched by CVE ID, not by vendor name.