Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

givanz — Vulnerabilities & Security Advisories 51

Browse all 51 CVE security advisories affecting givanz. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Givanz operates as a provider of enterprise security solutions, primarily focusing on email security and data loss prevention services for organizations seeking to mitigate communication-based threats. Historical vulnerability assessments reveal a pattern of critical flaws, including remote code execution and cross-site scripting, which have frequently allowed attackers to bypass authentication mechanisms or inject malicious scripts into administrative interfaces. These weaknesses often stemmed from insufficient input validation and improper access controls within the platform’s web application layer. While specific major public incidents remain limited in detailed reporting, the accumulation of twenty-one Common Vulnerabilities and Exposures highlights persistent challenges in maintaining robust security hygiene. The recurring nature of these issues suggests that legacy codebases or rapid feature deployment cycles may have occasionally outpaced rigorous security testing protocols, necessitating continuous patching and configuration reviews to protect user data integrity.

Top products by givanz: Vvveb Vvvebjs
CVE ID Title CVSS Severity Published
CVE-2026-54506 Vvveb: Stored XSS via sanitizeHTML() bypass in user profile bio field — Vvveb CWE-79 7.6 High 2026-09-17
CVE-2026-54612 Vvveb: Authenticated editor path traversal to PHP file write/RCE via data-v-save-global — Vvveb CWE-22 8.8 High 2026-09-17
CVE-2026-54613 Vvveb: Path Traversal in Revision Backup Reader/Deleter via Unsanitized theme Parameter — Vvveb CWE-22 5.4 Medium 2026-09-17
CVE-2026-54507 Vvveb oEmbedProxy vulnerable to server-side request forgery — Vvveb CWE-918 8.4 High 2026-09-17
CVE-2026-49223 Vvveb product review authorization bypass allows Vendors to read, approve, edit, or delete reviews under other Vendors' products — Vvveb CWE-639 7.6 High 2026-08-18
CVE-2026-49224 Vvveb post revision authorization bypass allows Authors to read, restore, or delete other Authors' post revisions — Vvveb CWE-639 8.3 High 2026-08-18
CVE-2026-49222 Vvveb product question authorization bypass allows Vendors to read, approve, edit, or delete questions under other Vendors' products — Vvveb CWE-639 7.6 High 2026-08-18
CVE-2026-49225 Vvveb product revision authorization bypass allows Vendors to read, restore, or delete other Vendors' product revisions — Vvveb CWE-639 8.3 High 2026-08-18
CVE-2026-49228 Vvveb product authorization bypass allows Vendors to read, duplicate, or delete other Vendors' products — Vvveb CWE-639 8.8 High 2026-08-18
CVE-2026-49226 Vvveb post authorization bypass allows Authors to view, duplicate, or delete other Authors' posts — Vvveb CWE-639 8.3 High 2026-08-18
CVE-2026-49227 Vvveb comment authorization bypass allows Authors to read, approve, edit, or delete comments under other Authors' posts — Vvveb CWE-639 7.6 High 2026-08-18
CVE-2026-49221 Vvveb digital asset authorization bypass allows Vendors to list, read, edit, or delete other Vendors' digital assets — Vvveb CWE-639 8.8 High 2026-08-18
CVE-2026-46408 Vvveb: checkout IDOR allows unauthorized reuse of another user's cart — Vvveb CWE-639 7.6 High 2026-05-15
CVE-2026-46407 Vvveb: admin/auth-token IDOR allows unauthorized disclosure of administrator REST API tokens — Vvveb CWE-639 8.1 High 2026-05-15
CVE-2026-45800 Vvveb: Authenticated SQL injection in /user/orders via order_by and direction — Vvveb CWE-89 - - 2026-05-15
CVE-2026-45622 Vvveb: Unauthenticated reflected XSS in public product return form via customer_order_id — Vvveb CWE-79 - - 2026-05-15
CVE-2026-45616 Vvveb: Stored XSS in Posts allows privilege escalation via post editor — Vvveb CWE-79 - - 2026-05-15
CVE-2026-44826 Vvveb: Vvveb CMS — Negative-quantity cart manipulation allows creation of orders with negative grand totals — Vvveb CWE-1284 7.5 High 2026-05-15
CVE-2026-44366 Vvveb: Stored XSS via Comment Author Field — Vvveb CWE-79 6.1 Medium 2026-05-15
CVE-2026-41937 Vvveb < 1.0.8.3 Unrestricted File Upload RCE via Plugin Upload — Vvveb CWE-434 7.2 High 2026-05-14
CVE-2026-41935 Vvveb < 1.0.8.3 Uncontrolled Recursion Denial of Service — Vvveb CWE-674 7.1 High 2026-05-14
CVE-2026-41933 Vvveb < 1.0.8.3 Directory Listing Information Disclosure — Vvveb CWE-548 5.3 Medium 2026-05-14
CVE-2026-41932 Vvveb < 1.0.8.3 Stored XSS via Signup Controller — Vvveb CWE-79 6.1 Medium 2026-05-14
CVE-2026-41928 Vvveb < 1.0.8.2 Information Disclosure via Cron Controller — Vvveb CWE-497 5.3 Medium 2026-05-07
CVE-2026-41929 Vvveb < 1.0.8.2 Unauthenticated Reflected XSS via Visual Editor — Vvveb CWE-79 6.1 Medium 2026-05-07
CVE-2026-41938 Vvveb < 1.0.8.2 RCE via Media Upload Handler — Vvveb CWE-434 8.8 High 2026-05-06
CVE-2026-41930 Vvveb < 1.0.8.2 Hard-coded Credentials Information Disclosure via phpMyAdmin — Vvveb CWE-306 9.8 Critical 2026-05-06
CVE-2026-41931 Vvveb < 1.0.8.2 Information Disclosure via Debug Exception Handler — Vvveb CWE-1188 5.3 Medium 2026-05-06
CVE-2026-41934 Vvveb < 1.0.8.2 Authenticated RCE via Code Editor — Vvveb CWE-184 8.8 High 2026-05-06
CVE-2026-41936 Vvveb < 1.0.8.2 XML External Entity Injection via Import — Vvveb CWE-611 8.1 High 2026-05-06

This page lists every published CVE security advisory associated with givanz. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.