VYPR

DFIR-IRIS

by Sbaresearch

CVEs (5)

  • CVE-2026-18362MedJul 30, 2026
    risk 0.00cvss 5.9epss 0.00

    The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.

  • CVE-2026-18361HigJul 30, 2026
    risk 0.00cvss 7.6epss 0.00

    The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.

  • CVE-2026-18360HigJul 30, 2026
    risk 0.00cvss 7.6epss 0.00

    The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function.

  • CVE-2026-16970MedJul 30, 2026
    risk 0.00cvss 4.2epss 0.00

    The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.

  • CVE-2026-16969HigJul 30, 2026
    risk 0.00cvss 7.6epss 0.00

    The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets function.