VYPR

Client

by DocuForm GmbH

CVEs (2)

  • CVE-2026-51925HigJul 9, 2026
    risk 0.00cvss 8.1epss 0.01

    A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to execute arbitrary code via the dfm-menu_report.php component. Attackers can exploit this flaw to read arbitrary files on the server, including sensitive…

  • CVE-2026-51923HigJul 9, 2026
    risk 0.00cvss 8.1epss 0.01

    An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code via the user settings component, and modify or retrieve sensitive data associated with other users’ accounts.