VYPR

Umami

by Umami Software

CVEs (1)

  • CVE-2026-4317CriMar 31, 2026
    risk 0.60cvss epss 0.00

    SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which could allow an authenticated attacker to execute arbitrary SQL commands in the database.Specifically, they could manipulate the value of the 'timezone' request…