VYPR
Vendor

Suitenumerique

Products
3
CVEs
5
Across products
5
Status
Private

Products

3

Recent CVEs

5
  • CVE-2026-3739MedMar 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in suitenumerique messages 0.2.0. This issue affects the function ThreadAccessSerializer of the file src/backend/core/api/serializers.py of the component ThreadAccess. The manipulation results in improper authentication. The attack can be…

  • CVE-2026-92800MedSep 16, 2026
    risk 0.37cvss 6.8epss 0.00

    Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read and write access to sub-documents through open websocket sessions that are never disconnected.

  • CVE-2026-91081MedSep 14, 2026
    risk 0.31cvss 5.8epss 0.00

    Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID. Attackers can exploit DNS time-of-check-time-of-use race conditions and shared…

  • CVE-2026-42185MedMay 8, 2026
    risk 0.29cvss 5.5epss 0.00

    People is an application to handle users and teams, and distribute permissions across La Suite. Prior to version 1.25.0, a user holding the Administrator role on a mail domain could send a crafted invitation request to promote any existing user (including users with no current…

  • CVE-2026-22867HigJan 15, 2026
    risk 0.00cvss 8.7epss 0.00

    LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 3.8.0 to 4.3.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Interlinking feature. When a user creates a link to another document within the editor, the URL of that link is not…