VYPR

Iris

by Dfir Iris

CVEs (6)

  • CVE-2026-41522HigJun 4, 2026
    risk 0.46cvss epss 0.00

    Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to version 2.4.28, DFIR-IRIS exposes an optional GraphQL endpoint at `/graphql` that does not enforce the same authorization checks as the REST API. Any…

  • CVE-2024-25624MedApr 25, 2024
    risk 0.44cvss 6.8epss 0.01

    Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations. Due to an improper setup of Jinja2 environment, reports generation in `iris-web` is prone to a Server Side Template Injection (SSTI). Successful exploitation…

  • CVE-2023-30615MedMay 25, 2023
    risk 0.41cvss 6.3epss 0.00

    Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations. A stored Cross-Site Scripting (XSS) vulnerability has been identified in iris-web, affecting multiple locations . The vulnerability in allows an attacker to…

  • CVE-2024-25640MedFeb 19, 2024
    risk 0.30cvss 4.6epss 0.00

    Iris is a web collaborative platform that helps incident responders share technical details during investigations. A stored Cross-Site Scripting (XSS) vulnerability has been identified in iris-web, affecting multiple locations in versions prior to v2.4.0. The vulnerability may…

  • CVE-2023-50712MedDec 22, 2023
    risk 0.30cvss 4.6epss 0.00

    Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations. A stored Cross-Site Scripting (XSS) vulnerability has been identified in iris-web, affecting multiple locations in versions prior to v2.3.7. The vulnerability…

  • CVE-2026-22783CriJan 12, 2026
    risk 0.00cvss 9.6epss 0.00

    Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to 2.4.24, the DFIR-IRIS datastore file management system has a vulnerability where mass assignment of the file_local_name field combined with path trust in…