VYPR

mygardyn

by Mygardyn

CVEs (3)

  • CVE-2026-25197CriApr 3, 2026
    risk 0.59cvss 9.1epss 0.00

    A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.

  • CVE-2026-54477MedJul 3, 2026
    risk 0.35cvss 5.4epss 0.00

    The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks.

  • CVE-2026-28767MedApr 3, 2026
    risk 0.34cvss 5.3epss 0.00

    A specific administrative endpoint notifications is accessible without proper authentication.