Vvveb Information Disclosure Vulnerability in Cron Controller
Vulnerability
An information disclosure vulnerability has been identified in Vvveb versions prior to 1.0.8.2. The issue resides in the cron controller, where unauthenticated attackers can access the application's secret cron key. This key, once retrieved, allows attackers to execute scheduled tasks outside of their intended timing.
Impact
Exploitation of this vulnerability could lead to unauthorized execution of scheduled tasks, potentially disrupting application functionality or causing other unintended effects.
Remediation
Users can update to Vvveb version 1.0.8.2 or later to address this vulnerability.
Added: May 7, 2026, 10:38 PM
Updated: May 7, 2026, 10:38 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
8.1remediation
0.0relevance
7.7threat
3.2urgency
2.9incentive
4.2Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
