VYPR

AutoBangumi

by AutoBangumi

CVEs (2)

  • CVE-2026-58466Jul 2, 2026
    risk 0.00cvss epss 0.01

    AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the administrator by using the publicly known default credentials seeded at startup via add_default_user() in the database user module when…

  • CVE-2026-59101Jul 2, 2026
    risk 0.00cvss epss 0.00

    AutoBangumi before 3.2.8 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote attackers to probe internal network services by supplying arbitrary host values to an unprotected setup endpoint. Attackers can send requests to the POST…