VYPR

community

by Documize

CVEs (1)

  • CVE-2026-71234Aug 5, 2026
    risk 0.00cvss epss

    Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a `secure` query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0), without…