VYPR

Meona Server Component

by Mesalvo

CVEs (5)

  • CVE-2026-22314HigMay 20, 2026
    risk 0.51cvss 7.9epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49;…

  • CVE-2026-0856HigMay 20, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper Access Control vulnerability in Mesalvo MEONA (MEONA Client and MEONA Server) allows an authenticated MEONA user to access administrative functions of the MEONA Client (admin panel). The MEONA Server does not independently verify the role asserted by the MEONA Client. A…

  • CVE-2026-0857MedMay 20, 2026
    risk 0.29cvss 4.4epss 0.00

    Use of a Password Hash With Insufficient Computational Effort in Mesalvo MEONA (MEONA Server and MEONA Client) for user accounts whose password was last set under a version before MEONA 2024.10. MEONA versions before 2024.10 protected stored passwords with SHA-1 (versions from…

  • CVE-2026-25602LowMay 20, 2026
    risk 0.15cvss 2.3epss 0.00

    Insufficient Verification of Data Authenticity in the feedback function of Mesalvo MEONA (MEONA Client and MEONA Server). The MEONA Client transmits the recipient address of a feedback report to the MEONA Server, and the server sends the report to the transmitted address instead…

  • CVE-2026-22315May 20, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.