VYPR

Biloop

by Adiss

CVEs (1)

  • CVE-2026-12686Jul 6, 2026
    risk 0.00cvss epss 0.00

    An authenticated user could manipulate a company ID parameter in a POST request to the backend to gain unauthorised access to other companies hosted within the same subdomain environment. The application does not adequately verify whether the requested company ID belongs to the…