VYPR

isquad

by Isquad

CVEs (1)

  • CVE-2026-81677HigAug 27, 2026
    risk 0.57cvss epss

    The ‘/ws/apiprensa/getVideo’ endpoint is vulnerable to SQL injection due to improper validation of the GET parameter `id_ambito`. An attacker can inject SQL syntax that breaks the underlying structure of the MariaDB query, resulting in syntax errors and the exposure of…