VYPR

Oss

by Geo Chen

Source repositories

CVEs (26)

  • CVE-2026-91998CriSep 15, 2026
    risk 0.64cvss 9.9epss 0.00

    Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizations. Attackers can enumerate user records…

  • CVE-2026-61518HigAug 19, 2026
    risk 0.57cvss 8.8epss 0.00

    ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id parameter passed to delete and update API methods is concatenated directly into SQL WHERE clauses without integer casting or parameterized query binding. The built-in SQL injection…

  • CVE-2026-92815HigSep 16, 2026
    risk 0.49cvss 7.5epss 0.00

    changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses. Attackers can supply arbitrary internal URLs in the optional_value parameter to retrieve responses from restricted network…

  • CVE-2026-92816HigSep 16, 2026
    risk 0.44cvss 7.8epss 0.00

    ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory. Attackers can load a crafted workflow that writes attacker-controlled content to arbitrary locations, enabling code…

  • CVE-2026-92812MedSep 16, 2026
    risk 0.44cvss 6.8epss 0.00

    decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation. Attackers can access sibling directories whose names begin with the repository directory name to read, write, or…

  • CVE-2026-80210MedAug 27, 2026
    risk 0.42cvss 6.5epss 0.00

    FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the _token hidden field in every form it renders, but only admin/users.php and admin/change_current_user_password.php call check_csrf_token() to validate it. No…

  • CVE-2026-78203HigAug 24, 2026
    risk 0.39cvss 7.1epss 0.00

    Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attackers to attach client-scoped templates from other clients to their own reports. Attackers can exploit sequential template primary keys to enumerate and attach…

  • CVE-2026-80211MedAug 27, 2026
    risk 0.38cvss 5.9epss 0.00

    FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin/users.php passes md5($_POST['password']) to add_user() and update_user_password(), admin/change_current_user_password.php does the same when a user changes their own password, the…

  • CVE-2026-92811MedSep 16, 2026
    risk 0.35cvss 6.5epss 0.00

    browserless versions 1.44.0 through 2.56.7 fail to enforce file protocol restrictions in Playwright websocket endpoints, allowing authenticated token holders to read arbitrary files. Attackers can navigate Playwright-driven browsers to file scheme URLs and access files…

  • CVE-2026-78204MedAug 24, 2026
    risk 0.35cvss 5.4epss 0.00

    Ghostwriter through 7.2.6 does not apply per-object authorization on its report template lint endpoints. RoleBasedAccessControlMixin.test_func returns only request.user.is_active unless a view overrides it, and neither the endpoint that lints a report template nor the endpoint…

  • CVE-2026-91997MedSep 15, 2026
    risk 0.34cvss 5.3epss 0.00

    evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint. Attackers can bypass IP whitelist restrictions to access sensitive metrics disclosing…

  • CVE-2026-65698MedJul 23, 2026
    risk 0.34cvss 5.3epss 0.00

    Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside the open workspace by injecting instructions into content the agent processes. Attackers can supply absolute…

  • CVE-2026-92814MedSep 16, 2026
    risk 0.27cvss 4.2epss 0.00

    changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markup injection. Attackers can place malicious markup in monitored page titles that reaches notification channels like email and Telegram as live content when the…

  • CVE-2026-92810MedSep 16, 2026
    risk 0.21cvss 4.3epss 0.00

    PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential wishlist identifiers to obtain valid…

  • CVE-2026-92809MedSep 16, 2026
    risk 0.21cvss 4.3epss 0.00

    PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged consent records for other customers, corrupting audit logs.

  • CVE-2026-65702HigJul 23, 2026
    risk 0.00cvss 8.6epss 0.01

    Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated remote attackers to write attacker-controlled JSON files to arbitrary filesystem locations and read conversation metadata from…

  • CVE-2026-65701CriJul 23, 2026
    risk 0.00cvss 9.1epss 0.01

    SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltrate arbitrary files by supplying attacker-controlled filesystem paths through the…

  • CVE-2026-65700CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.02

    h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process by supplying traversal sequences in the bearer token. The…

  • CVE-2026-65699MedJul 23, 2026
    risk 0.00cvss 4.2epss 0.00

    AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_id in the request body without ownership verification. The…

  • CVE-2026-65697MedJul 23, 2026
    risk 0.00cvss 6.1epss 0.00

    Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that allows unauthenticated attackers to inject a javascript: URI into the Top Pages dashboard by supplying a crafted hostname and pathname to the unauthenticated…

Page 1 of 2