CVE-2025-8517: medium-severity vulnerability in givanz Vvveb
givanz Vvveb session fixiation
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 2.2%
exploitation probability
2.2%top 18% of all CVEs
observed exploitation
nono source reports it
A vulnerability was detected in givanz Vvveb 1.0.6.1. Impacted is an unknown function. The manipulation results in session fixiation. The attack can be launched remotely. The exploit is now public and may be used. Upgrading to version 1.0.7 is recommended to address this issue. The patch is identified as d4b1e030066417b77d15b4ac505eed5ae7bf2c5e. You should upgrade the affected component.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
givanz · VvvebRelated CVEs — givanz Vvveb
In the same product, most dangerous first.
CVE-2025-8518MEDIUMgivanz Vvveb Code Editor code.php save code injectionEPSS 2.1%CVE-2026-39918CRITICALVvveb < 1.0.8.1 Code Injection via Installation EndpointEPSS 1.1%CVE-2026-41938HIGHVvveb < 1.0.8.2 RCE via Media Upload HandlerEPSS 1.0%CVE-2026-34427HIGHVvveb < 1.0.8.1 Privilege Escalation via admin/user/saveEPSS 1.0%CVE-2026-41934HIGHVvveb < 1.0.8.2 Authenticated RCE via Code EditorEPSS 1.0%CVE-2026-54612HIGHVvveb: Authenticated editor path traversal to PHP file write/RCE via data-v-save-globalEPSS 0.8%
References
https://github.com/givanz/Vvveb/commit/d4b1e030066417b77d15b4ac505eed5ae7bf2c5ehttps://github.com/givanz/Vvveb/issues/312https://github.com/givanz/Vvveb/issues/312#issuecomment-2977995664https://github.com/givanz/Vvveb/releases/tag/1.0.7https://github.com/helloandrewpaul/Session-Fixation-in-Vvveb-CMS-v1.0.6.1https://github.com/kwerty138/Session-Fixation-in-Vvveb-CMS-v1.0.6.1https://vuldb.com/?ctiid.318643https://vuldb.com/?id.318643https://vuldb.com/?submit.623135