mygardyn
by Mygardyn
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-25197 | Cri | 0.59 | 9.1 | 0.00 | Apr 3, 2026 | A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call. | ||
| CVE-2026-54477 | Med | 0.35 | 5.4 | 0.00 | Jul 3, 2026 | The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks. | ||
| CVE-2026-28767 | Med | 0.34 | 5.3 | 0.00 | Apr 3, 2026 | A specific administrative endpoint notifications is accessible without proper authentication. |
- risk 0.59cvss 9.1epss 0.00
A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.
- risk 0.35cvss 5.4epss 0.00
The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks.
- risk 0.34cvss 5.3epss 0.00
A specific administrative endpoint notifications is accessible without proper authentication.