VYPR

CTI-Transmute

by CTI Transmute

CVEs (2)

  • CVE-2026-69082Aug 3, 2026
    risk 0.00cvss epss 0.00

    CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. The /account/delete/ endpoint accepted HTTP GET requests for an operation that modified application state. An unauthenticated remote attacker could…

  • CVE-2026-69079Aug 3, 2026
    risk 0.00cvss epss 0.00

    CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint. The endpoint accepts a user-controlled days query parameter that was not restricted to a reasonable range. A remote, unauthenticated attacker could…