VYPR

Advanced Forms

by Kiteworks

CVEs (2)

  • CVE-2026-102121HigSep 30, 2026
    risk 0.56cvss 8.6epss —

    A form-rendering interface in the Advanced Forms component is reachable without authentication so that published forms can be displayed to anonymous visitors, but it returned more data than the form itself required. Anyone who knew the web address of a published form could…

  • CVE-2026-102150HigSep 30, 2026
    risk 0.47cvss 7.2epss —

    A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did not permit access to user accounts, stored…