VYPR

Web Image Monitor

by Ricoh

CVEs (3)

  • CVE-2019-25324MedFeb 12, 2026
    risk 0.40cvss 6.1epss 0.00

    RICOH Web Image Monitor 1.09 contains an HTML injection vulnerability in the address configuration CGI script that allows attackers to inject malicious HTML code. Attackers can exploit the entryNameIn and entryDisplayNameIn parameters to insert arbitrary HTML content, potentially enabling cross-site scripting attacks.

  • CVE-2025-41393MedMay 12, 2025
    risk 0.40cvss 6.1epss 0.01

    Reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor. If exploited, an arbitrary script may be executed on the web browser of the user who accessed Web Image Monitor. As for the details of affected product names and versions, refer to the information provided by the vendors under [References].

  • CVE-2026-41226MedApr 30, 2026
    risk 0.31cvss 4.7epss 0.00

    Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web Image Monitor. When accessing a specially crafted URL, the user may be redirected to an arbitrary website. As a result, the user may become a victim of a phishing attack.