/Vulnerability Library

VvvebJs <= 2.0.5 - Cross-Site Scripting

CVE-2026-5615
Verified

Description

Givanz Vvvebjs <= 2.0.5 contains a stored XSS caused by manipulation of the "uploadAllowExtensions" argument in upload.php File Upload Endpoint, letting remote attackers execute scripts, exploit requires crafted input.

Severity

Medium

CVSS Score

4.3

Exploit Probability

1%

Published Date

April 6, 2026

Template Author

theamanrawat

CVE-2026-5615.yaml
4.3Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVE ID:
cve-2026-5615
CWE ID:
cwe-79

References

https://github.com/advisories/GHSA-p873-9x3v-gmvhhttps://github.com/givanz/VvvebJs

Remediation Steps

Apply the patch 8cac22cff99b8bc701c408aa8e887fa702755336 or update to the fixed version.