VYPR
Vendor

Sync

Products
8
CVEs
4
Across products
11
Status
Private

Products

8

Recent CVEs

4
  • CVE-2019-20191HigMar 16, 2020
    risk 0.49cvss 7.5epss 0.01

    Oxygen XML Editor 21.1.1 allows XXE to read any file.

  • CVE-2021-46827MedJul 13, 2022
    risk 0.40cvss 6.1epss 0.00

    An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS vulnerability in search terms proposals (in online documentation generated using Oxygen XML WebHelp) allows attackers to execute JavaScript by convincing a…

  • CVE-2023-26559MedApr 14, 2023
    risk 0.35cvss 5.3epss 0.01

    A directory traversal vulnerability in Oxygen XML Web Author before 25.0.0.3 build 2023021715 and Oxygen Content Fusion before 5.0.3 build 2023022015 allows an attacker to read files from a WEB-INF directory via a crafted HTTP request. (XML Web Author 24.1.0.3 build 2023021714…

  • CVE-2025-48464MedOct 8, 2025
    risk 0.31cvss 4.7epss 0.00

    Successful exploitation of the vulnerability could allow an unauthenticated attacker to gain access to a victim’s Sync account data such as account credentials and email protection information.