VYPR

Jabref

by Jabref

Source repositories

CVEs (2)

  • CVE-2018-1000652CriAug 20, 2018
    risk 0.65cvss 10.0epss 0.02

    JabRef version <=4.3.1 contains a XML External Entity (XXE) vulnerability in MsBibImporter XML Parser that can result in disclosure of confidential data, denial of service, server side request forgery, port scanning. This attack appear to be exploitable via Specially crafted…

  • CVE-2026-53534HigSep 17, 2026
    risk 0.42cvss —epss 0.00

    JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef's built-in HTTP server is enabled, the GET /better-bibtex/cayw endpoint accepts an external command query parameter and CAYWQueryParams.getCommand() passes it…