VYPR
Vendor

Fangtang7

Products
8
CVEs
6
Across products
7
Status
Private

Products

8

Recent CVEs

6
  • CVE-2026-79569CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

  • CVE-2026-75330CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.00

    The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through StringUtils.split() and string concatenation without being…

  • CVE-2026-79571CriSep 8, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off sale, finish/cancel orders, and modify categories without…

  • CVE-2026-75332CriAug 26, 2026
    risk 0.59cvss 9.1epss 0.00

    Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().

  • CVE-2026-79575HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.00

    The JWT signing secret in yfexam-exam v2.0 is derived from the username and the current month instead of a random server-side key, making the secret key easily obtainable via a bruteforce attack.

  • CVE-2026-75333HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist validation.