VYPR

WebControl CMS

by Intermark IT

CVEs (2)

  • CVE-2026-6954Jun 30, 2026
    risk 0.00cvss epss 0.00

    Cross-Site Scripting (XSS) vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to execute JavaScript code or inject a dynamic iframe into the victim’s browser by sending a malicious URL via the 'urlDestino' parameter in '/portal.do'. This…

  • CVE-2026-6953Jun 30, 2026
    risk 0.00cvss epss 0.00

    HTML injection vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to send an email containing malicious HTML code to a victim via the contact form. To exploit this vulnerability, the attacker must send a request using the…