VYPR

Docs

by Suitenumerique

Source repositories

CVEs (4)

  • CVE-2026-92800MedSep 16, 2026
    risk 0.37cvss 6.8epss 0.00

    Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read and write access to sub-documents through open websocket sessions that are never disconnected.

  • CVE-2026-76907MedSep 24, 2026
    risk 0.35cvss 6.5epss 0.00

    LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 4.8.2 until 5.4.0, GET /api/v1.0/documents/search/ accepts sequential seven-digit document paths to scope descendant searches without requiring the caller to possess the public document UUID. An…

  • CVE-2026-91081MedSep 14, 2026
    risk 0.31cvss 5.8epss 0.00

    Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID. Attackers can exploit DNS time-of-check-time-of-use race conditions and shared…

  • CVE-2026-22867HigJan 15, 2026
    risk 0.00cvss 8.7epss 0.00

    LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 3.8.0 to 4.3.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Interlinking feature. When a user creates a link to another document within the editor, the URL of that link is not…