CVE-2026-5615General

LOWCVSS 2.1 · LOW

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in givanz Vvvebjs up to 2.0.5. The affected element is an unknown function of the file upload.php of the component File Upload Endpoint. This manipulation of the argument uploadAllowExtensions causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. Patch name: 8cac22cff99b8bc701c408aa8e887fa702755336. Applying a patch is the recommended action to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-06: 4PoC Mentioned / Linked · 2026-04-06: 1Exploit Tool / Code · 2026-04-06: 1Technical Details · 2026-04-06: 204-06
Signal classification3 categories
General
250.0%
Disclosure
125.0%
PoC
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • pdnuclei-bot@pdnuclei_bot
    PoC

    🚨 CVE-2026-5615 - medium 🚨 VvvebJs <= 2.0.5 - Cross-Site Scripting > Givanz Vvvebjs <= 2.0.5 contains a stored XSS caused by manipulation of the "uploadAl... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-5615 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post introduces CVE‑2026‑5615 as a medium‑severity stored XSS in VvvebJs, shares a Nuclei template link as a PoC, but offers no evidence of active exploitation or patch availability.

    00040228
    960 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5615 - givanz Vvvebjs File Upload Endpoint upload.php cross site scripting Intel Report: https://ift.tt/H6uT0rz

    Post summary

    The alert announces CVE‑2026‑5615 as a cross‑site scripting flaw in a file‑upload endpoint, but offers no PoC, exploit code, active exploitation evidence, or patch information.

    0000036
    281 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5615 A weakness has been identified in givanz Vvvebjs up to 2.0.5. The affected element is an unknown function of the file upload.php of the component File Upload Endpoint. … https://www.cve.org/CVERecord?id=CVE-2026-5615 ----- Traducción: CVE-2026-5615 Se … http://infoflow.cloud`

    Post summary

    The post briefly announces CVE-2026-5615, noting a weakness in the file upload component of Givanz Vvvebjs up to 2.0.5, but does not provide technical details, PoC, patch, or exploitation evidence.

    0000033
    67 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5615 A weakness has been identified in givanz Vvvebjs up to 2.0.5. The affected element is an unknown function of the file upload.php of the component File Upload Endpoint. … https://www.cve.org/CVERecord?id=CVE-2026-5615

    Post summary

    The post notes a weakness in givanz Vvvebjs’ file upload component but offers no actionable details on exploitation, patching, or technical specifics.

    00000219
    57.0K followersView on X

Explore more