VYPR

Vedo Suite

by Vedo Suite

CVEs (4)

  • CVE-2025-51055HigAug 6, 2025
    risk 0.56cvss 8.6epss 0.00

    Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 2024.17. This file contains clear-text credentials, secret keys, and database information.

  • CVE-2025-51056HigAug 6, 2025
    risk 0.53cvss 8.2epss 0.01

    An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write to arbitrary filesystem paths by exploiting the insecure 'uploadPreviews()' custom function in '/api_vedo/colorways_preview', ultimately resulting in remote…

  • CVE-2025-51057MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.01

    A local file inclusion (LFI) vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'readfile()' function call in '/api_vedo/video/preview'.

  • CVE-2025-51054MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Vedo Suite 2024.17 is vulnerable to Incorrect Access Control, which allows remote attackers to obtain a valid high privilege JWT token without prior authentication via sending an empty HTTP POST request to the /autologin/ API endpoint.