Aller au contenu

Fiche vulnérabilité

CVE-2025-11029 : faille élevée vvveb vvveb (CVSS 8.8)

Description

A weakness has been identified in givanz Vvveb up to 1.0.7.2. This vulnerability affects unknown code. Executing manipulation can lead to cross-site request forgery. The attack can be executed remotely. The exploit has been made available to the public and could be exploited. Once again the project maintainer reacted very professional: "I accept the existence of these vulnerabilities. (...) I fixed the code to remove these vulnerabilities and will push the code to github and make a new release."

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
26 sept. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • vvveb vvveb

Références

Rechercher une autre vulnérabilité dans la base CVE