VYPR

Webbox

by Tobit Laboratories AG

CVEs (2)

  • CVE-2026-54214MedAug 7, 2026
    risk 0.34cvss epss 0.00

    Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL parameter, which allows arbitrary modification of the Content-Type header in HTTP responses. Because the parameter does not properly restrict control…

  • CVE-2026-12071MedAug 7, 2026
    risk 0.34cvss epss 0.00

    The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input, which is appended to the redirect target in a 302 HTTP response. By using URL-encoded characters such as “%2e” (representing a dot), an attacker can manipulate the…