VYPR

SmartSign

by ProCertum

CVEs (2)

  • CVE-2026-57917Jul 27, 2026
    risk 0.00cvss epss 0.00

    proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a…

  • CVE-2026-57916Jul 27, 2026
    risk 0.00cvss epss 0.00

    proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it to the victim. When the victim opens the…