VYPR

Kaiten

by Kaiten

CVEs (3)

  • CVE-2026-79303CriSep 15, 2026
    risk 0.64cvss 9.9epss 0.00

    kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injection. Dynamic SQL statements are generated without the required data validation and without using parameterized statements or stored procedures.

  • CVE-2024-41276CriOct 1, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application requires users to input a 6-digit PIN code sent to their email for authorization after entering their login credentials. However, the request…

  • CVE-2024-39211MedJul 4, 2024
    risk 0.35cvss 5.3epss 0.01

    Kaiten 57.128.8 allows remote attackers to enumerate user accounts via a crafted POST request, because a login response contains a user_email field only if the user account exists.