VYPR

NewsBlur

by NewsBlur

CVEs (2)

  • CVE-2026-56772Jun 25, 2026
    risk 0.00cvss epss 0.00

    NewsBlur before 14.5.0 contains a broken access control vulnerability that allows authenticated users to read private notification feeds by supplying arbitrary user_id values to the GET /social/interactions endpoint without ownership verification. Attackers can enumerate user_id…

  • CVE-2026-56771Jun 25, 2026
    risk 0.00cvss epss 0.00

    NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows authenticated users to make arbitrary server requests to internal networks by failing to filter private IP addresses. Attackers can exploit this to access…