VYPR

scheduleR

by Scheduler

CVEs (3)

  • CVE-2026-31072CriMay 19, 2026
    risk 0.64cvss 9.8epss 0.01

    The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization. The unmarshal_object function allows for arbitrary class instantiation and state injection by dynamically…

  • CVE-2024-45982HigSep 26, 2024
    risk 0.57cvss 8.8epss 0.00

    A host header injection vulnerability in scheduleR v0.0.18 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and compromise their accounts.

  • CVE-2020-37077MedFeb 3, 2026
    risk 0.42cvss 6.5epss 0.01

    Booked Scheduler 2.7.7 contains a directory traversal vulnerability in the manage_email_templates.php script that allows authenticated administrators to access unauthorized files. Attackers can exploit the vulnerable 'tn' parameter to read files outside the intended directory by…