VYPR

Client

by DocuForm GmbH

CVEs (2)

  • CVE-2026-51923Jul 9, 2026
    risk 0.00cvss epss 0.00

    An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code via the user settings component, and modify or retrieve sensitive data associated with other users’ accounts.

  • CVE-2026-51925Jul 9, 2026
    risk 0.00cvss epss 0.00

    A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to execute arbitrary code via the dfm-menu_report.php component. Attackers can exploit this flaw to read arbitrary files on the server, including sensitive…