VYPR

Documenso

by Documenso

Source repositories

CVEs (4)

  • CVE-2024-52271HigDec 5, 2024
    risk 0.53cvss epss 0.00

    User Interface (UI) Misrepresentation of Critical Information vulnerability in Documenso allows Content Spoofing.Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the…

  • CVE-2026-82472HigAug 29, 2026
    risk 0.42cvss 7.5epss

    Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust storage resources or fill the database…

  • CVE-2026-71247MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields belonging to any later-or-equal-order, not-yet-signed recipient in the same envelope, with no restriction on field type. A newer V2…

  • CVE-2026-13543MedJun 29, 2026
    risk 0.00cvss 5.6epss 0.01

    A vulnerability was detected in Documenso up to 2.11.0. Affected by this vulnerability is an unknown functionality of the file packages/auth/server/lib/utils/handle-oauth-callback-url.ts of the component Google OAuth Login. The manipulation results in improper authentication. It…

VYPR — Vulnerability Intelligence