VYPR
Vendor
Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2026-31382Med0.406.10.00Mar 20, 2026The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-specific onpagereveal payload.
CVE-2026-31381Med0.345.30.00Mar 20, 2026An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL.