VYPR
Vendor

Bookcars

Products
1
CVEs
6
Across products
6
Status
Private

Products

1

Recent CVEs

6
  • CVE-2026-36721CriJun 9, 2026
    risk 0.64cvss 9.8epss 0.00

    A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.

  • CVE-2026-36727CriJun 9, 2026
    risk 0.59cvss 9.1epss 0.00

    An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.

  • CVE-2026-36723HigJun 9, 2026
    risk 0.57cvss 8.8epss 0.01

    An unrestricted file rename vulnerability in the /api/create-user component of bookcars v8.3 allows authenticated attackers to leverage directory traversal sequences to move arbitrary files from temporary storage to arbitrary locations on the server filesystem. This enables…

  • CVE-2026-36720HigJun 9, 2026
    risk 0.53cvss 8.1epss 0.00

    Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to admin via modifying their user type.

  • CVE-2026-36722MedJun 9, 2026
    risk 0.35cvss 5.4epss 0.00

    An authenticated arbitrary file upload vulnerability in the /api/create-car-image component of bookcars v8.3 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2026-36726MedJun 9, 2026
    risk 0.34cvss 5.3epss 0.01

    An arbitrary file deletion vulnerability in the /api/delete-temp-license/{file} endpoint of bookcars v8.3 allows unauthenticated attackers to delete arbitrary files via supplying directory traversal sequences.