VYPR

Eramba Enterprise and Community edition

by Eramba

CVEs (2)

  • CVE-2023-36255HigAug 3, 2023
    risk 0.65cvss 8.8epss 0.53

    An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path parameter in the URL.

  • CVE-2025-55462MedJan 13, 2026
    risk 0.42cvss 6.5epss 0.00

    A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header to be reflected in the Access-Control-Allow-Origin response along with Access-Control-Allow-Credentials: true. This permits malicious third-party websites to…