VYPR

Flamingo

by VITEC Exterity

CVEs (2)

  • CVE-2026-61498Jul 13, 2026
    risk 0.00cvss epss 0.02

    Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters in the start, end, key, or format HTTP GET…

  • CVE-2026-60121Jul 13, 2026
    risk 0.00cvss epss 0.01

    Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument handling. The endpoint applies…