VYPR

NL Portal

by Nl Portal

CVEs (2)

  • CVE-2026-49464higJul 8, 2026
    risk 0.45cvss epss

    ## Impact In versions from 1.5.0 up to and including 3.0.0, any authenticated portal user could complete and tamper with another user's open task by submitting it on their behalf. The task submission endpoint accepted a task ID and a payload, but it never checked whether the…

  • CVE-2026-49463medJul 8, 2026
    risk 0.26cvss epss

    ## Impact In versions up to and including 3.0.0, two parts of the GraphQL API returned data without checking whether the data belonged to the logged-in user: - **Document content.** A logged-in user could download the raw content of any document by its ID, regardless of who…