VYPR

node-api-postgres

by JawherKl

CVEs (2)

  • CVE-2026-4191HigMar 16, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in JawherKl node-api-postgres up to 2.5. Affected is the function path.extname of the file index.js of the component Profile Picture Handler. This manipulation causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has…

  • CVE-2026-4190HigMar 16, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in JawherKl node-api-postgres up to 2.5. This impacts the function User.getAll of the file models/user.js. The manipulation of the argument sort results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.…