VYPR

Vedo Suite

by Bottinelli Informatical

CVEs (3)

  • CVE-2026-51366CriAug 19, 2026
    risk 0.64cvss 9.9epss 0.01

    SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter

  • CVE-2026-51367HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.01

    An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to obtain sensitive information via the api_vedo/chat endpoint and the utente_chat parameter

  • CVE-2025-51058MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Bottinelli Informatical Vedo Suite 2024.17 is vulnerable to Server-side Request Forgery (SSRF) in the /api_vedo/video/preview endpoint, which allows remote authenticated attackers to trigger HTTP requests towards arbitrary remote paths via the "file" URL parameter.