VYPR

Archerysec

by Archerysec

CVEs (2)

  • CVE-2026-92765MedSep 16, 2026
    risk 0.42cvss 6.5epss

    ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to retrieve complete web vulnerability data…

  • CVE-2019-20008MedDec 26, 2019
    risk 0.35cvss 5.4epss 0.01

    In Archery before 1.3, inserting an XSS payload into a project name (either by creating a new project or editing an existing one) will result in stored XSS on the vulnerability-scan scheduling page.