Known CVE
VvvebJs <= 2.0.5 - Cross-Site Scripting
Givanz Vvvebjs <= 2.0.5 contains a stored XSS caused by manipulation of the "uploadAllowExtensions" argument in upload.php File Upload Endpoint, letting remote attackers execute scripts, exploit requires crafted input.
CVE-2026-5615
Medium2026CVSS 4.3CWE-79
cve2026 · xss · stored-xss · file-upload · svg · vvvebjs
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website