VYPR

rebuild

by Getrebuild

CVEs (4)

  • CVE-2025-50900CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in getrebuild/rebuild 4.0.4. The affected source code class is com.rebuild.web.RebuildWebInterceptor, and the affected function is preHandle In the filter code, use CodecUtils.urlDecode(request.getRequestURI()) to obtain the URL-decoded request path, and…

  • CVE-2024-25294CriMar 20, 2024
    risk 0.59cvss 9.1epss 0.01

    An SSRF issue in REBUILD v.3.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the FileDownloader.java, proxyDownload,URL parameters.

  • CVE-2024-46413MedAug 25, 2025
    risk 0.33cvss 5.1epss 0.00

    Rebuild v3.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the type parameter in the com.rebuild.web.admin.rbstore.RBStoreController#loadDataIndex method.

  • CVE-2023-2474MedMay 2, 2023
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in Rebuild 3.2 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is…