VYPR

Weberpmesv2

by Smewebify

Source repositories

CVEs (4)

  • CVE-2026-49827CriAug 13, 2026
    risk 0.57cvss 9.8epss 0.00

    WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open…

  • CVE-2025-52130MedAug 25, 2025
    risk 0.35cvss 5.4epss 0.00

    File upload vulnerability in WebErpMesv2 1.17 in the app/Http/Controllers/FactoryController.php controller. This flaw allows an authenticated attacker to upload arbitrary files, including PHP scripts, which can be accessed via direct GET requests, potentially resulting in remote…

  • CVE-2026-22789MedJan 12, 2026
    risk 0.00cvss 5.4epss 0.00

    WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, WebErpMesv2 contains a file upload validation bypass vulnerability in multiple controllers that allows authenticated users to upload arbitrary files, including PHP scripts,…

  • CVE-2026-22788HigJan 12, 2026
    risk 0.00cvss 8.2epss 0.01

    WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, the WebErpMesV2 application exposes multiple sensitive API endpoints without authentication middleware. An unauthenticated remote attacker can read business-critical data…