VYPR

WebMeasure

by Lewe

CVEs (1)

  • CVE-2025-40697MedFeb 19, 2026
    risk 0.33cvss epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in '/index.php' in Lewe WebMeasure, which allows remote attackers to execute arbitrary code through the 'page' parameter. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.