VYPR
Vendor

Odysseus Blog

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2026-70619HigAug 4, 2026
    risk 0.50cvss 8.8epss 0.00

    Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that verify session authentication but omit the admin…

  • CVE-2026-70620MedAug 4, 2026
    risk 0.37cvss 6.8epss 0.00

    Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to probe internal network resources by supplying arbitrary URLs to the embedding endpoint configuration without scheme, host, IP range,…

  • CVE-2006-6951Jan 23, 2007
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in blog.php in OdysseusBlog allows remote attackers to inject arbitrary web script or HTML via the page parameter.