VYPR

WAPT

by Wapt

CVEs (1)

  • CVE-2026-75132MedAug 31, 2026
    risk 0.42cvss 6.5epss

    WAPT Server versions 2.6.1.17834 and earlier contains a SQL injection vulnerability in the `columns` parameter of the GET `/api/v3/hosts` endpoint. A remote authenticated user with read-only privileges can inject arbitrary PostgreSQL expressions into the SQL query constructed by…