VYPR

DocSys

by DocSys

CVEs (2)

  • CVE-2026-75327CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.00

    In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability:

  • CVE-2026-75413HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize the downloadDocEx.do interface and download any file via the parameter targetPath.