VYPR

Pentestify

by Pentestify

Source repositories

CVEs (3)

  • CVE-2026-59231MedJul 31, 2026
    risk 0.27cvss epss 0.00

    Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server to arbitrary attacker-chosen destinations via unvalidated URLs stored in the finding images field or the…

  • CVE-2026-19744MedAug 13, 2026
    risk 0.26cvss epss

    Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitrary JavaScript in the application origin via a Markdown link whose URL contains a double quote, which closes the anchor's href attribute because the…

  • CVE-2026-19716MedAug 13, 2026
    risk 0.26cvss epss

    Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated user via a crafted username, because the frontend escapes the…