VYPR

Virtualizor

by Softaculous

CVEs (3)

  • CVE-2026-43641CriSep 22, 2026
    risk 0.64cvss 9.8epss 0.03

    Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authentication through specific parameter…

  • CVE-2026-43642HigSep 22, 2026
    risk 0.53cvss 8.1epss 0.01

    Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing module handler that allows unauthenticated remote attackers to supply arbitrary serialized PHP objects for deserialization by setting the act parameter to login…

  • CVE-2026-43643HigSep 22, 2026
    risk 0.49cvss 7.5epss 0.01

    Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing module handler that allows unauthenticated remote attackers to modify any tenant's account balance by supplying crafted act and from_billing_module parameters…