VYPR

craftplan

by Puemos

CVEs (1)

  • CVE-2026-76876MedAug 21, 2026
    risk 0.31cvss 5.9epss

    Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sensitive credentials by exploiting an unconditional authorization policy on the Settings resource. Attackers can send a GET request to the settings API endpoint…