VYPR

ezBookkeeping

by MaysWind

Source repositories

CVEs (4)

  • CVE-2024-57604CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.

  • CVE-2025-65519MedFeb 18, 2026
    risk 0.42cvss 6.5epss 0.00

    mayswind ezbookkeeping versions 1.2.0 and earlier contain a critical vulnerability in JSON and XML file import processing. The application fails to validate nesting depth during parsing operations, allowing authenticated attackers to trigger denial of service conditions by…

  • CVE-2024-57603MedFeb 12, 2025
    risk 0.41cvss 6.3epss 0.00

    An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the lack of rate limiting.

  • CVE-2026-94112MedSep 20, 2026
    risk 0.37cvss 6.8epss 0.00

    mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window. Attackers with stolen credentials can authenticate and reuse a captured passcode against multiple authorization attempts…