VYPR

Aimeos Base

by Aimeos

CVEs (1)

  • CVE-2026-49262lowJun 26, 2026
    risk 0.07cvss epss

    ### Summary The administrative proxy route (`cmsproxy`) in Aimeos Pagible CMS is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding. A Time-of-Check to Time-of-Use (TOCTOU) race condition exists between the URL validation phase and the actual HTTP…