VYPR
Vendor

Codecanyon

Products
12
CVEs
14
Across products
14
Status
Private

Products

12

Recent CVEs

14
  • CVE-2023-38912CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Super Store Finder PHP Script v.3.6 allows a remote attacker to execute arbitrary code via a crafted payload to the username parameter.

  • CVE-2023-4407MedAug 18, 2023
    risk 0.44cvss 6.3epss 0.01

    A vulnerability classified as critical was found in Codecanyon Credit Lite 1.5.4. Affected by this vulnerability is an unknown functionality of the file /portal/reports/account_statement of the component POST Request Handler. The manipulation of the argument date1/date2 leads to…

  • CVE-2026-7783MedMay 5, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in CodeCanyon Perfex CRM up to 3.4.1. This vulnerability affects the function AbstractKanban::applySortQuery of the file application/services/AbstractKanban.php of the component Admin Kanban Endpoint. This manipulation of the argument this causes sql…

  • CVE-2025-11304MedOct 5, 2025
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in CodeCanyon/ui-lib Mentor LMS up to 1.1.1. Affected by this vulnerability is an unknown functionality of the component API. Executing manipulation can lead to permissive cross-domain policy with untrusted domains. The attack may be launched remotely. The…

  • CVE-2024-8945MedSep 17, 2024
    risk 0.40cvss 5.5epss 0.15

    A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. This vulnerability affects unknown code of the file /index.php/dashboard/save. The manipulation of the argument id leads to sql injection. The attack can be initiated…

  • CVE-2026-19966MedAug 17, 2026
    risk 0.35cvss 5.4epss

    A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue affects some unknown processing of the file /clients/save_contact of the component Contact Information Update. Such manipulation of the argument contact_id leads to authorization…

  • CVE-2024-0545MedJan 15, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability classified as problematic was found in CodeCanyon RISE Ultimate Project Manager 3.5.3. This vulnerability affects unknown code of the file /index.php/signin. The manipulation of the argument redirect with the input http://evil.com leads to open redirect. The…

  • CVE-2025-3855MedApr 22, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in CodeCanyon RISE Ultimate Project Manager 3.8.2 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php/team_members/save_profile_image/ of the component Profile Picture Handler. The manipulation of…

  • CVE-2025-3219LowApr 4, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in CodeCanyon Perfex CRM 3.2.1. It has been classified as problematic. Affected is an unknown function of the file /perfex/clients/project/2 of the component Project Discussions Module. The manipulation of the argument description leads to cross site…

  • CVE-2025-2974LowMar 31, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in CodeCanyon Perfex CRM up to 3.2.1 and classified as problematic. This vulnerability affects unknown code of the file /contract of the component Contracts. The manipulation of the argument content leads to cross site scripting. The attack can be…

  • CVE-2024-9031LowSep 20, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, has been found in CodeCanyon CRMGo SaaS up to 7.2. This issue affects some unknown processing of the file /project/task/{task_id}/show. The manipulation of the argument comment leads to cross site scripting. The attack may be…

  • CVE-2024-9030LowSep 20, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability classified as problematic was found in CodeCanyon CRMGo SaaS 7.2. This vulnerability affects unknown code of the file /deal/{note_id}/note. The manipulation of the argument notes leads to cross site scripting. The attack can be initiated remotely. The exploit has…

  • CVE-2023-3787LowJul 20, 2023
    risk 0.23cvss 3.5epss 0.01

    A vulnerability classified as problematic was found in Codecanyon Tiva Events Calender 1.4. This vulnerability affects unknown code. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the…

  • CVE-2014-8954Nov 17, 2014
    risk 0.03cvss epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in phpSound 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Title or (2) Description fields in a playlist or the (3) filter parameter in an explore action to index.php.