VYPR
Vendor

Hashtopolis

Products
2
CVEs
3
Across products
3
Status
Private

Products

2

Recent CVEs

3
  • CVE-2017-11681HigJul 27, 2017
    risk 0.57cvss 8.8epss 0.01

    Incorrect Access Control vulnerability in Hashtopussy 0.4.0 allows remote authenticated users to execute actions that should only be available for administrative roles, as demonstrated by an action=createVoucher request to agents.php.

  • CVE-2017-11682MedJul 27, 2017
    risk 0.40cvss 6.1epss 0.01

    Stored Cross-site scripting vulnerability in Hashtopussy 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) version, (2) url, or (3) rootdir parameter in hashcat.php.

  • CVE-2026-22104HigJul 17, 2026
    risk 0.00cvss epss 0.00

    Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read all cracked hashes of a Hashtopolis server instance.