VYPR

Wacrm

by Arnasdon

Source repositories

CVEs (2)

  • CVE-2026-49141HigJun 8, 2026
    risk 0.39cvss 7.1epss 0.00

    WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body…

  • CVE-2026-67530MedJul 30, 2026
    risk 0.35cvss 6.4epss 0.00

    WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earlier, the automation send_webhook action in src/lib/automations/engine.ts and its validation in src/lib/automations/validate.ts allowed an authenticated user with automation privileges to submit an arbitrary…