VYPR

Organization Portal System

by Wellchoose

CVEs (9)

  • CVE-2026-3826CriMar 11, 2026
    risk 0.64cvss 9.8epss 0.01

    IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.

  • CVE-2025-8913CriAug 13, 2025
    risk 0.64cvss 9.8epss 0.01

    Organization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.

  • CVE-2025-8912HigAug 13, 2025
    risk 0.49cvss 7.5epss 0.01

    Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.

  • CVE-2025-8914MedAug 13, 2025
    risk 0.42cvss 6.5epss 0.00

    Organization Portal System developed by WellChoose has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

  • CVE-2025-8909MedAug 13, 2025
    risk 0.42cvss 6.5epss 0.01

    Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.

  • CVE-2026-3825MedMar 11, 2026
    risk 0.40cvss 6.1epss 0.00

    IFTOP developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing authenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

  • CVE-2026-3824MedMar 11, 2026
    risk 0.40cvss 6.1epss 0.00

    IFTOP developed by WellChoose has an Open redirect vulnerability, allowing authenticated remote attackers to craft a URL that tricks users into visiting malicious website.

  • CVE-2025-8911MedAug 13, 2025
    risk 0.40cvss 6.1epss 0.00

    Organization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

  • CVE-2025-8910MedAug 13, 2025
    risk 0.40cvss 6.1epss 0.00

    Organization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.