Vulnerabilidades en givanz

51 resultados
Análisis Vexday

A givanz possui 39 vulnerabilidades registradas, com preocupação elevada pelo volume recente: 18 CVEs publicadas nos últimos 90 dias, sinalizando ritmo de descobertas acelerado. Embora nenhuma esteja sob ataque ativo no momento e apenas 2 sejam críticas, a fraqueza dominante (CWE-79, injeção de scripts) indica padrão sistemático de falhas em validação de entrada, típico de controles de segurança deficientes no desenvolvimento.

CVE-2026-49226HIGHVvveb post authorization bypass allows Authors to view, duplicate, or delete other Authors' postsEPSS 0.5%CVE-2026-41935HIGHVvveb < 1.0.8.3 Uncontrolled Recursion Denial of ServiceEPSS 0.5%CVE-2026-54507HIGHVvveb oEmbedProxy vulnerable to server-side request forgeryEPSS 0.4%CVE-2026-34428HIGHVvveb < 1.0.8.1 SSRF via oEmbedProxyEPSS 0.4%CVE-2026-45622MEDIUMVvveb: Unauthenticated reflected XSS in public product return form via customer_order_idEPSS 0.4%CVE-2026-41933MEDIUMVvveb < 1.0.8.3 Directory Listing Information DisclosureEPSS 0.4%CVE-2026-41931MEDIUMVvveb < 1.0.8.2 Information Disclosure via Debug Exception HandlerEPSS 0.4%CVE-2026-49223HIGHVvveb product review authorization bypass allows Vendors to read, approve, edit, or delete reviews under other Vendors' productsEPSS 0.4%CVE-2026-49222HIGHVvveb product question authorization bypass allows Vendors to read, approve, edit, or delete questions under other Vendors' productsEPSS 0.4%CVE-2026-49227HIGHVvveb comment authorization bypass allows Authors to read, approve, edit, or delete comments under other Authors' postsEPSS 0.4%CVE-2025-8519MEDIUMgivanz Vvveb Drag-and-Drop Editor editor information disclosureEPSS 0.4%CVE-2026-45616MEDIUMVvveb: Stored XSS in Posts allows privilege escalation via post editorEPSS 0.4%CVE-2026-41932MEDIUMVvveb < 1.0.8.3 Stored XSS via Signup ControllerEPSS 0.4%CVE-2026-46407HIGHVvveb: admin/auth-token IDOR allows unauthorized disclosure of administrator REST API tokensEPSS 0.4%CVE-2025-9728MEDIUMgivanz Vvveb login.tpl cross site scriptingEPSS 0.4%CVE-2025-11026MEDIUMgivanz Vvveb Configuration File information disclosureEPSS 0.4%CVE-2025-12203MEDIUMgivanz Vvveb Code Editor functions.php sanitizeFileName path traversalEPSS 0.4%CVE-2026-44826HIGHVvveb: Vvveb CMS — Negative-quantity cart manipulation allows creation of orders with negative grand totalsEPSS 0.4%CVE-2025-8520MEDIUMgivanz Vvveb Drag-and-Drop Editor editor server-side request forgeryEPSS 0.4%CVE-2026-45800HIGHVvveb: Authenticated SQL injection in /user/orders via order_by and directionEPSS 0.3%