VYPR

Streama

by Streamaserver

Source repositories

CVEs (2)

  • CVE-2025-34452HigDec 18, 2025
    risk 0.50cvss epss 0.05

    Streama versions 1.10.0 through 1.10.5 and prior to commit b7c8767 contain a combination of path traversal and server-side request forgery (SSRF) vulnerabilities in that allow an authenticated attacker to write arbitrary files to the server filesystem. The issue exists in the…

  • CVE-2026-73039MedAug 13, 2026
    risk 0.28cvss 5.4epss 0.00

    streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated users to read and delete other users' viewing status records. Attackers can enumerate all users' watch progress, delete arbitrary viewing history, and…