VYPR

Wapt Server

by Wapt

CVEs (2)

  • CVE-2026-33591CriAug 3, 2026
    risk 0.65cvss epss 0.01

    A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.

  • CVE-2026-75132MedAug 31, 2026
    risk 0.42cvss 6.5epss 0.00

    WAPT Server versions 2.6.1.17834 and earlier contains a SQL injection vulnerability in the `columns` parameter of the GET `/api/v3/hosts` endpoint. A remote authenticated user with read-only privileges can inject arbitrary PostgreSQL expressions into the SQL query constructed by…