Givanz Vvvebjs <= 2.0.5 contains a stored XSS caused by manipulation of the "uploadAllowExtensions" argument in upload.php File Upload Endpoint, letting remote attackers execute scripts, exploit requires crafted input.
id: CVE-2026-5615
info:
name: VvvebJs <= 2.0.5 - Cross-Site Scripting
author: theamanrawat
se
...