VYPR
Vendor

TaleLin

Products
3
CVEs
7
Across products
8
Status
Private

Products

3

Recent CVEs

7
  • CVE-2020-18701CriAug 16, 2021
    risk 0.64cvss 9.8epss 0.02

    Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's authentication token upon logout, which allows for replaying packets.

  • CVE-2020-18698CriAug 16, 2021
    risk 0.64cvss 9.8epss 0.02

    Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'.

  • CVE-2024-41600HigJul 19, 2024
    risk 0.49cvss 7.5epss 0.00

    Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component.

  • CVE-2022-32430HigJul 21, 2022
    risk 0.49cvss 7.5epss 0.05

    An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application.

  • CVE-2026-10152MedMay 30, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in TaleLin lin-cms-spring-boot up to 0.2.1. This issue affects some unknown processing of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. The manipulation results in improper access…

  • CVE-2020-18699MedAug 16, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts in the the 'Username' parameter of the in component 'app/api/cms/user.py'.

  • CVE-2025-15151LowDec 28, 2025
    risk 0.24cvss 3.7epss 0.00

    A vulnerability was determined in TaleLin Lin-CMS up to 0.6.0. This affects an unknown part of the file /tests/config.py of the component Tests Folder. This manipulation of the argument username/password causes password in configuration file. The attack is possible to be carried…