Skip to content

Known CVE

VvvebJs <= 2.0.5 - Cross-Site Scripting

Givanz Vvvebjs <= 2.0.5 contains a stored XSS caused by manipulation of the "uploadAllowExtensions" argument in upload.php File Upload Endpoint, letting remote attackers execute scripts, exploit requires crafted input.

CVE-2026-5615

Medium2026CVSS 4.3CWE-79

cve2026 · xss · stored-xss · file-upload · svg · vvvebjs

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website