VYPR

GEOFlow

by Yaojingang

CVEs (4)

  • CVE-2026-82667MedAug 31, 2026
    risk 0.24cvss 4.7epss

    A vulnerability has been found in yaojingang GEOFlow up to 2.1.0. Impacted is the function DistributionController.isValidHttpEndpoint of the file app/Services/GeoFlow/GenericHttpEndpointResolver.php. Such manipulation of the argument endpoint_url leads to server-side request…

  • CVE-2026-82666MedAug 31, 2026
    risk 0.24cvss 4.7epss

    A flaw has been found in yaojingang GEOFlow up to 2.1.0. This issue affects the function preview of the file app/Http/Controllers/Admin/SiteThemeEditorController.php of the component Superadmin Theme Editor. This manipulation of the argument blade causes code injection. It is…

  • CVE-2026-82664MedAug 31, 2026
    risk 0.21cvss 4.3epss

    A security vulnerability has been detected in yaojingang GEOFlow up to 2.1.0. This affects an unknown part of the file app/Http/Controllers/Site/HomeController.php of the component JSON-LD Theme Handler. The manipulation of the argument Search leads to cross site scripting. The…

  • CVE-2026-82665LowAug 31, 2026
    risk 0.18cvss 3.8epss

    A vulnerability was detected in yaojingang GEOFlow up to 2.1.0. This vulnerability affects the function unlink of the file app/Http/Controllers/Admin/ImageLibraryController.php of the component Image Library Cleanup. The manipulation of the argument file_path results in path…