VYPR

Opensign

by Opensignlabs

Source repositories

CVEs (10)

  • CVE-2026-72548HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.00

    An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any organisation tenant record via the gettenant Parse cloud function. The function accepts a contactId parameter and returns the full tenant…

  • CVE-2026-72545HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.00

    An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to write to any contact record via the updatecontacttour Parse cloud function. The function performs no authentication or authorization before…

  • CVE-2026-72544HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.00

    An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to forge document audit-trail entries via the triggerevent Parse cloud function. The function accepts viewer identity and IP address as caller-supplied…

  • CVE-2026-72543HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.00

    An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any contact record via the getcontact Parse cloud function. The function executes with useMasterKey and performs no authentication or…

  • CVE-2026-72692HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.00

    A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to irreversibly decline any in-flight document and forge the decline attribution to an arbitrary user via the declinedoc Parse cloud function. The…

  • CVE-2026-72691HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.00

    An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl Parse cloud function. The function skips its…

  • CVE-2026-72689HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.00

    A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents using useMasterKey, bypassing the…

  • CVE-2026-72688HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.01

    A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read arbitrary stored documents via the fileupload Parse cloud function. The function mints MASTER_KEY-signed file access tokens for any…

  • CVE-2026-92794HigSep 16, 2026
    risk 0.42cvss 7.5epss 0.00

    OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verification is disabled. Attackers can supply a document identifier from guest signing links to retrieve complete document details including all signers'…

  • CVE-2026-72549MedAug 11, 2026
    risk 0.34cvss 5.3epss 0.00

    An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to map any email address or username to its internal user objectId via the getUserId Parse cloud function. The function performs no authentication before…