VYPR
Vendor

Banq

Products
1
CVEs
9
Across products
9
Status
Private

Products

1

Recent CVEs

9
  • CVE-2026-107828MedOct 8, 2026
    risk 0.42cvss 6.5epss —

    Jivejdon through 5.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access Weibo-created accounts by deriving predictable credentials from public Weibo user IDs. OAuthAccountServiceImp.transferSina() sets the password to the first four…

  • CVE-2026-107797MedOct 8, 2026
    risk 0.40cvss 6.1epss —

    Jivejdon through 5.0 contains a reflected cross-site scripting vulnerability in application/message/postThread.jsp that allows attackers to inject script via the to and tag parameters. Attackers can send crafted links to authenticated users, breaking out of unencoded inline…

  • CVE-2026-107796MedOct 8, 2026
    risk 0.40cvss 6.1epss —

    Jivejdon from commit 5489372d through commit ee67a65e contains a reflected cross-site scripting vulnerability in application/query/taggedThreadList.jsp that allows unauthenticated attackers to inject script via unencoded tagID and count parameters. Attackers can craft a link…

  • CVE-2026-107829MedOct 8, 2026
    risk 0.38cvss 5.9epss —

    Jivejdon through 5.0 contains a weak password storage vulnerability that stores account passwords as unsalted MD5 digests via ToolsUtil.hash() in AccountDaoSql. Attackers who obtain the user table through database access or SQL injection can crack passwords with precomputed…

  • CVE-2026-107800MedOct 8, 2026
    risk 0.35cvss 5.4epss —

    Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script into private short messages because receiveshortmessage.jsp renders unfiltered message bodies. Attackers can send a short message containing script,…

  • CVE-2026-107798MedOct 8, 2026
    risk 0.35cvss 5.4epss —

    jivejdon from commit 595d8d22 through commit ee67a65e contains a stored cross-site scripting vulnerability in the default-enabled TextStyle filter that inserts unvalidated URLs into anchor href attributes. Authenticated attackers can post messages with javascript: links or…

  • CVE-2026-107830MedOct 8, 2026
    risk 0.34cvss 5.3epss —

    Jivejdon from commit e0306088 through commit ee67a65e lacks rate limiting on the unauthenticated /account/smsVRAction endpoint handled by SmsQQAction, allowing unlimited SMS sending. Attackers can load newAccount.jsp to set session attributes, then repeatedly call the endpoint…

  • CVE-2026-107831MedOct 8, 2026
    risk 0.28cvss 4.3epss —

    Jivejdon through 5.0 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing actions by abusing GET endpoints lacking anti-CSRF tokens. Attackers can lure authenticated users to crafted links targeting /account/protected/delAll,…

  • CVE-2026-107793MedOct 8, 2026
    risk 0.28cvss 4.3epss —

    Jivejdon through 5.0 contains an authorization bypass vulnerability in SubscriptionServiceImp.deleteSubscription that allows authenticated users to delete other users' subscriptions by ID. Attackers can submit a delete action to /account/protected/sub/subSaveAction with another…