PT-2025-31855 · Unknown · Givanz Vvveb

0Xhamy

·

Published

2025-08-04

·

Updated

2025-08-04

·

CVE-2025-8521

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions givanz Vvveb versions up to 1.0.5
Description A cross-site scripting issue exists due to unknown processing of the file /vadmin123/index.php?module=settings/post-types within the Add Type Handler component. The attack can be initiated remotely. The exploit has been publicly disclosed.
Recommendations Upgrade to version 1.0.6 to address this issue.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-8521

Affected Products

Givanz Vvveb