VYPR
Vendor

Contentful

Products
2
CVEs
2
Across products
2
Status
Private

Products

2

Recent CVEs

2
  • CVE-2020-13258MedMay 21, 2020
    risk 0.40cvss 6.1epss 0.02

    Contentful through 2020-05-21 for Python allows reflected XSS, as demonstrated by the api parameter to the-example-app.py.

  • CVE-2026-53957higAug 19, 2026
    risk 0.38cvss epss

    ### Summary `export_space` and `import_space` tools in `@contentful/mcp-tools` accept LLM-controlled `host` and `proxy` parameters that are spread directly into the options object passed to `contentful-export` / `contentful-import`. These libraries pass the merged options —…