VYPR
Vendor

Pantsel

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2023-39846CriAug 16, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token.

  • CVE-2024-34243MedMay 14, 2024
    risk 0.35cvss 5.4epss 0.00

    Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter.

  • CVE-2021-42192HigMay 4, 2022
    risk 0.01cvss 8.8epss 0.10

    Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.