VYPR

Document Management System

by Openkm

Source repositories

CVEs (3)

  • CVE-2026-41917MedMay 26, 2026
    risk 0.32cvss 4.9epss

    OpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interface at /admin/Scripting that allows authenticated administrators to read arbitrary files by supplying an attacker-controlled filesystem path through the fsPath parameter with…

  • CVE-2019-11445Apr 22, 2019
    risk 0.05cvss epss 0.21

    OpenKM 6.3.2 through 6.3.7 allows an attacker to upload a malicious JSP file into the /okm:root directories and move that file to the home directory of the site, via frontend/FileUpload and admin/repository_export.jsp. This is achieved by interfering with the Filesystem path…

  • CVE-2009-1503May 1, 2009
    risk 0.03cvss epss 0.00

    Multiple SQL injection vulnerabilities in login.php in Tiger Document Management System (DMS) allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.