VYPR

ThriveX Blogging Framework

by ThriveX

CVEs (1)

  • CVE-2025-57266CriSep 29, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in file AssistantController.java in ThriveX Blogging Framework 2.5.9 thru 3.1.3 allowing unauthenticated attackers to gain sensitive information such as API Keys via the /api/assistant/list endpoint.