VYPR

Reportico

by Reportico Web

Source repositories

CVEs (9)

  • CVE-2026-52608CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecuteCode attribute of any report regardless of the safe_mode setting leading to remote code execution.

  • CVE-2026-52610CriAug 18, 2026
    risk 0.59cvss 9.1epss 0.01

    An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user by specifying a filename in the "saveTemplate" parameter in conjuction…

  • CVE-2024-31556HigMay 14, 2024
    risk 0.44cvss 7.8epss 0.00

    An issue in Reportico Web before v.8.1.0 allows a local attacker to execute arbitrary code and obtain sensitive information via the sessionid function.

  • CVE-2026-52607MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.01

    A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or execute arbitrary php files on the web server by specifying the filename in the target_format parameter in conjunction with the execute_mode=EXECUTE parameter of the run.php…

  • CVE-2023-48865MedApr 11, 2024
    risk 0.42cvss 6.5epss 0.01

    An issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via execute_mode parameter of the URL.

  • CVE-2023-47438MedMar 27, 2024
    risk 0.42cvss 6.5epss 0.00

    SQL Injection vulnerability in Reportico Till 8.1.0 allows attackers to obtain sensitive information or other system information via the project parameter.

  • CVE-2026-52609MedAug 18, 2026
    risk 0.40cvss 6.1epss 0.00

    A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the reportico_criteria parameter in conjunction with the execute_mode=CRITERIA…

  • CVE-2026-52606MedAug 18, 2026
    risk 0.40cvss 6.1epss 0.00

    A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the loadTemplate parameter in conjunction with the execute_mode=PREPARE…

  • CVE-2023-46925MedNov 2, 2023
    risk 0.31cvss 4.8epss 0.00

    Reportico 7.1.21 is vulnerable to Cross Site Scripting (XSS).