VYPR

badaso

by Uasoft

CVEs (2)

  • CVE-2026-19376HigAug 10, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. The manipulation leads to permission issues. It is possible to initiate the attack remotely. The…

  • CVE-2025-15398LowDec 31, 2025
    risk 0.24cvss 3.7epss 0.01

    A security vulnerability has been detected in Uasoft badaso up to 2.9.7. Affected is the function forgetPassword of the file src/Controllers/BadasoAuthController.php of the component Token Handler. Such manipulation leads to weak password recovery. The attack can be executed…