VYPR

Pentestify

by Ccyl13

Source repositories

CVEs (6)

  • CVE-2026-13150MedJun 24, 2026
    risk 0.38cvss epss 0.00

    Server-Side Request Forgery (SSRF) (CWE-918) in the PDF generation endpoint GET /api/reports/{id}/pdf (backend/main.py) in ccyl13 Pentestify 1.0.0 and lower allows remote attackers to make the server issue requests to arbitrary internal or external URLs, including cloud metadata…

  • CVE-2026-59231MedJul 31, 2026
    risk 0.27cvss epss 0.00

    Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server to arbitrary attacker-chosen destinations via unvalidated URLs stored in the finding images field or the…

  • CVE-2026-76203MedAug 19, 2026
    risk 0.26cvss epss 0.00

    Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer Pentestify 1.2.0 through 2.3.2 allows an authenticated user to force outbound HTTP requests from other users' browsers, disclosing their IP address and User-Agent, via CSS hex…

  • CVE-2026-19744MedAug 13, 2026
    risk 0.26cvss epss 0.00

    Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitrary JavaScript in the application origin via a Markdown link whose URL contains a double quote, which closes the anchor's href attribute because the…

  • CVE-2026-19716MedAug 13, 2026
    risk 0.26cvss epss 0.00

    Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated user via a crafted username, because the frontend escapes the…

  • CVE-2026-19434MedAug 11, 2026
    risk 0.26cvss epss 0.00

    Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the application origin via HTML markup stored in a finding's severity field, which the frontend interpolates unescaped into class and…