VYPR

66biolinks

by AltumCode

CVEs (3)

  • CVE-2025-69602CriJan 28, 2026
    risk 0.59cvss 9.1epss 0.00

    A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate the session identifier after successful authentication. As a result, the same session cookie value is reused for users logging in from the same browser, allowing…

  • CVE-2025-69601MedJan 28, 2026
    risk 0.42cvss 6.5epss 0.01

    A directory traversal (Zip Slip) vulnerability exists in the “Static Sites” feature of 66biolinks v44.0.0 by AltumCode. Uploaded ZIP archives are automatically extracted without validating or sanitizing file paths. An attacker can include traversal sequences (e.g., ../) in…

  • CVE-2025-66939MedJan 12, 2026
    risk 0.35cvss 5.4epss 0.00

    Cross Site Scripting vulnerability in 66biolinks by AltumCode v.61.0.1 allows an attacker to execute arbitrary code via a crafted favicon file