CVE-2026-45800 | givanz Vvveb up to 1.0.8.3 Orders /user/orders OrderSQL::getAll sql injection (GHSA-vwcx-w4fq-9769 / EUVD-2026-30582)
A vulnerability marked as critical has been reported in givanz Vvveb up to 1.0.8.3. This vulnerability affects the function OrderSQL::getAll of the file /user/orders of the component Orders Component. The manipulation leads to sql injection.
This vulnerability is referenced as CVE-2026-45800. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.