VvvebJs <= 2.0.5 - Cross-Site Scripting
CVE-2026-5615
Verified
Description
Givanz Vvvebjs <= 2.0.5 contains a stored XSS caused by manipulation of the "uploadAllowExtensions" argument in upload.php File Upload Endpoint, letting remote attackers execute scripts, exploit requires crafted input.
Severity
Medium
CVSS Score
4.3
Exploit Probability
1%
Published Date
April 6, 2026
Template Author
theamanrawat
CVE-2026-5615.yaml
4.3Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVE ID:
cve-2026-5615
CWE ID:
cwe-79
Remediation Steps
Apply the patch 8cac22cff99b8bc701c408aa8e887fa702755336 or update to the fixed version.