VYPR
Vendor

Mosasauroidea

Products
2
CVEs
7
Across products
9
Status
Private

Products

2

Recent CVEs

7
  • CVE-2026-38474MedAug 25, 2026
    risk 0.35cvss 5.4epss 0.00

    GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 suffers from a Broken access control vulnerability in the IP lock manager, which allows remote authenticated users to add, modify, or delete IP lock entries for arbitrary accounts via…

  • CVE-2026-38467MedAug 25, 2026
    risk 0.35cvss 5.4epss 0.00

    A SQL injection vulnerability in the tags manager in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users with users_mod privileges to execute arbitrary SQL commands via the tagid or type parameter in a crafted POST…

  • CVE-2026-38473Aug 25, 2026
    risk 0.00cvss —epss 0.00

    A Stored XSS vulnerability in the subtitle deletion flow in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users to inject arbitrary JavaScript via a crafted subtitle filename, which is stored during upload and later…

  • CVE-2026-38470Aug 25, 2026
    risk 0.00cvss —epss 0.00

    A Broken access control vulnerability in the API user endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows unprivileged, authenticated users to enable or disable arbitrary user accounts via the req=disable or req=enable action using a…

  • CVE-2026-38469Aug 25, 2026
    risk 0.00cvss —epss 0.00

    A Stored XSS vulnerability in the custom bonus title feature in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users to inject arbitrary JavaScript via the title parameter in /bonus.php and /user.php?action=staff_tool.

  • CVE-2026-38468Aug 25, 2026
    risk 0.00cvss —epss 0.00

    A SQL injection vulnerability in the country-code lookup endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users with users_view_ips privileges to execute arbitrary SQL commands via the ip parameter in a crafted…

  • CVE-2026-38465Aug 25, 2026
    risk 0.00cvss —epss 0.00

    A Stored XSS vulnerability in the donor avatar mouse-over text feature in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users to inject arbitrary JavaScript via the avatar_mouse_over_text parameter, which is stored and…