VYPR

Databasement

by David Crty

Source repositories

CVEs (3)

  • CVE-2026-95654HigSep 22, 2026
    risk 0.41cvss 7.4epss 0.01

    Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization decision without re-checking token validity during acceptance. Attackers with a leaked or forwarded invitation link can load the page while pending, then accept…

  • CVE-2026-103534MedOct 1, 2026
    risk 0.34cvss 6.3epss —

    A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Model. This manipulation causes improper access controls. Remote exploitation of the…

  • CVE-2026-103533MedOct 1, 2026
    risk 0.20cvss 4.1epss —

    A vulnerability was found in David-Crty databasement up to 1.7.1. This impacts the function https:/github.com/David-Crty/databasement/pull/511 of the file app/Http/Requests/Api/V1/RestoreRequest.php of the component database-servers API Endpoint. The manipulation of the argument…