Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Vvveb

First CVE: Mar 22, 2024Active for: 2 yearsTotal CVEs: 38
49.4
VTI Score
High

Vvveb is a page-builder and website-creation platform with a focused but strategically positioned product line that includes its core builder and JavaScript components, placing it among more-prominent vendors in the vulnerability landscape despite a small overall portfolio. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency toward public exploit availability, consistent with the web-application and code-execution risks inherent to builder platforms. The exposure concentrates in the Vvveb builder and VvvebJS products and recurs through weakness classes including code injection, cross-site scripting, improper access control, unrestricted file uploads, and exposure of sensitive information—a pattern characteristic of platforms that handle user-supplied content and dynamic code generation. Defenders should treat builder-platform patches as high-priority given the downstream effect on generated websites and user data handling; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
38
Total CVEs
More Total CVEs than 98% of tracked vendors
6.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Vvveb over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 22, 2024
2 years ago
Most Recent CVE
May 14, 2026
71 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (38 CVEs).

38 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-8518HIGH
A vulnerability was found in givanz Vvveb 1.0.5. It has been rated as critical. Affected by this issue is the function Save of the file admin/controller/editor/code.php of the comp
Aug 4, 20257.240NOYES
CVE-2026-41930CRITICAL
Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration that allows unauthenticated attackers to access the bun
May 6, 20269.837NONO
CVE-2026-39918CRITICAL
Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parameter is written unsanitized into the env.php configuration fi
Apr 20, 20269.837NONO
CVE-2024-25182CRITICAL
givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.
Dec 29, 20259.834NONO
CVE-2024-25181CRITICAL
A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from
Dec 29, 20259.133NONO
CVE-2024-29272MEDIUM
Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sani
Mar 22, 20246.533NOYES
CVE-2026-34427HIGH
Vvveb prior to 1.0.8.1 contains a privilege escalation vulnerability in the admin user profile save endpoint that allows authenticated users to modify privileged fields on their ow
Apr 20, 20268.832NONO
CVE-2026-41938HIGH
Vvveb before version 1.0.8.2 contains an unrestricted file upload vulnerability in the media upload handler that allows authenticated users with media-upload permissions to bypass
May 6, 20268.831NONO
CVE-2026-41934HIGH
Vvveb before version 1.0.8.2 contains an authenticated remote code execution vulnerability in the admin code editor that allows low-privilege authenticated users to execute arbitra
May 6, 20268.831NONO
CVE-2024-27480CRITICAL
givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.
Dec 29, 20259.831NONO
View all 38 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products38 CVEs
45%
34%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network38 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low37 (97.4%)
High1 (2.6%)
Unknown0 (0.0%)
User Interaction
None28 (73.7%)
Unknown0 (0.0%)
Required10 (26.3%)
Privileges Required
Low13 (34.2%)
High6 (15.8%)
None19 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (38 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.6% of CVEs· 97th percentile
Nuclei
1 CVE
2.6% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Vvveb.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Vvveb — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Vvveb's Products

View all 3 CNAs →

Top CWEs