VYPR

Easyreport

by Xianrendzw

Source repositories

CVEs (4)

  • CVE-2026-75979MedAug 19, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected is the function execSqlText/previewSqlText of the file DesignerController.java of the component SQL Preview Endpoint. The manipulation of the argument sqlText results in improper neutralization…

  • CVE-2026-75978MedAug 19, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the function DataSourceController.add of the file DataSourceController.java of the component QueryerFactory. Such manipulation of the argument queryerClass leads…

  • CVE-2026-75876MedAug 18, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is some unknown functionality of the file ModuleController.java of the component Move Operations. Such manipulation of the argument sourcePath leads to sql…

  • CVE-2026-9524MedMay 26, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is the function execute of the component REST Endpoint. Executing a manipulation of the argument reportParams can lead to sql injection. The attack can be launched remotely. The vendor…