VYPR

Tcms

by Kiwitcms

CVEs (1)

  • CVE-2026-54724medJul 6, 2026
    risk 0.26cvss epss

    ### Summary An open redirect vulnerability in the account confirmation endpoint allows an unauthenticated attacker to craft a URL hosted on a legitimate Kiwi TCMS instance that redirects victims to an arbitrary external domain. The attack surface is particularly relevant for…