VYPR

BPS

by WEBCON

CVEs (2)

  • CVE-2026-92419MedSep 23, 2026
    risk 0.34cvss —epss 0.00

    WEBCON BPS is vulnerable to Insecure Direct Object Reference (IDOR) in the /api/vacations/{path} endpoint. The selectedPeople parameter in the Gantt vacation chart API does not validate whether the requesting user is authorized to access the requested users' data. An…

  • CVE-2026-1630MedMay 14, 2026
    risk 0.33cvss —epss 0.00

    WEBCON BPS is vulnerable to Reflected XSS via one of parameters used by "/openinmobileapp" endpoint. An attacker can send a specially crafted URL that, when opened by an authenticated user, results in arbitrary JavaScript execution in the victim's browser. This issue was fixed…