VYPR

ViewState add-on

by Zed Attack Proxy

CVEs (1)

  • CVE-2026-57527Jun 26, 2026
    risk 0.00cvss epss 0.00

    Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution by embedding a malicious serialized Java object in the javax.faces.ViewState…