VYPR
Vendor

pig-mesh

Products
2
CVEs
3
Across products
3
Status
Private

Products

2

Recent CVEs

3
  • CVE-2025-63691CriNov 7, 2025
    risk 0.62cvss 9.6epss 0.00

    In pig-mesh In Pig version 3.8.2 and below, within the Token Management function under the System Management module, the token query interface (/api/admin/sys-token/page) has an improper permission verification issue, which leads to information leakage. This interface can be…

  • CVE-2025-63690CriNov 7, 2025
    risk 0.59cvss 9.1epss 0.01

    In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the system management module, it is possible to execute any Java class with a parameterless constructor and its methods with parameter type String through…

  • CVE-2026-91995CriSep 15, 2026
    risk 0.52cvss 9.1epss

    pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password to…