VYPR

Next SaaS Stripe Starter

by Mickasmt

Source repositories

CVEs (3)

  • CVE-2026-4548MedMar 22, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in mickasmt next-saas-stripe-starter 1.0.0. Affected by this vulnerability is the function updateUserrole of the file actions/update-user-role.ts. The manipulation of the argument userId/role results in improper authorization. The attack may be…

  • CVE-2026-4547MedMar 22, 2026
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in mickasmt next-saas-stripe-starter 1.0.0. Affected is the function generateUserStripe of the file actions/generate-user-stripe.ts of the component Checkout Handler. The manipulation of the argument priceId leads to business logic…

  • CVE-2026-4549LowMar 22, 2026
    risk 0.20cvss 3.1epss 0.00

    A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization bypass. Remote exploitation of the attack…