VYPR
Vendor

Morelitea

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2026-28274HigFeb 26, 2026
    risk 0.57cvss 8.7epss 0.01

    Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to Stored Cross-Site Scripting (XSS) in the document upload functionality. Any user with upload permissions within the "Initiatives" section can upload a malicious…

  • CVE-2026-28275HigFeb 26, 2026
    risk 0.53cvss 8.1epss 0.00

    Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 do not invalidate previously issued JWT access tokens after a user changes their password. As a result, older tokens remain valid until expiration and can still be used to access…

  • CVE-2026-28276HigFeb 26, 2026
    risk 0.49cvss 7.5epss 0.00

    Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions prior to 0.32.2 where uploaded documents are served from a publicly accessible /uploads/ directory without any authentication or authorization checks. Any…