Remote Code Execution Vulnerability in vvveb CMS by Givanz
CVE-2025-44022

9.8CRITICAL

Key Information:

Vendor

Givanz

Status
Vendor
CVE Published:
12 May 2025

What is CVE-2025-44022?

A security flaw in vvveb CMS version 1.0.6 enables remote attackers to exploit the plugin mechanism, leading to arbitrary code execution. This vulnerability can allow a malicious actor to perform unauthorized actions on the affected system, demanding urgent attention from users and administrators to secure their installations and mitigate potential threats. Regular updates and security assessments are recommended to protect against such vulnerabilities.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.