VYPR

Download Station

by Qnap

CVEs (3)

  • CVE-2025-58465MedNov 7, 2025
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the…

  • CVE-2024-38640MedSep 6, 2024
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Download Station…

  • CVE-2025-58463MedNov 7, 2025
    risk 0.32cvss 4.9epss 0.00

    A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in…