VYPR
Vendor

Nl Portal

Products
7
CVEs
5
Across products
9
Status
Private

Products

7

Recent CVEs

5
  • CVE-2026-49464HigSep 11, 2026
    risk 0.46cvss 8.1epss 0.00

    NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:taak` package from version 1.5.0 through 3.0.0 fails to verify ownership when processing the…

  • CVE-2026-49463MedSep 11, 2026
    risk 0.35cvss 6.5epss 0.00

    NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:documenten-api` package through version 3.0.0 and the `nl.nl-portal:besluiten` package from…

  • CVE-2026-49462MedSep 11, 2026
    risk 0.27cvss 5.3epss 0.00

    NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. In versions up to and including 3.0.0, deployments using the shipped default configuration exposed two GraphQL…

  • CVE-2026-55414Jun 19, 2026
    risk 0.00cvss epss

    ## Summary The public GraphQL resolvers `getFormDefinitionByObjectenApiUrl(url)` and the deprecated `getFormDefinitionById(id)` fetch a caller-supplied URL using the **privileged Objecten-API token**. Because the `/graphql` endpoint is `permitAll()` and these resolvers do not…

  • CVE-2026-54683Jun 18, 2026
    risk 0.00cvss epss

    ## Summary A previous advisory (CVE-2026-49463 / GHSA-qpm9-h556-mwxm) reported that any logged-in user could download any document by its identifier, and stated this was fixed in 3.0.1. For the document-content part that fix was **incomplete**: documents remained downloadable…