VYPR

Security Advisories

by Kiteworks

Source repositories

CVEs (2)

  • CVE-2026-24751HigJun 1, 2026
    risk 0.53cvss 8.2epss

    Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker to trick a user into executing arbitrary JavaScript code. Upgrade Kiteworks to version 9.3.0 or later to receive a…

  • CVE-2026-23638MedJun 1, 2026
    risk 0.42cvss 6.5epss

    Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated attacker to tamper with the internal approval flow configurations of forms belonging to other users…