VYPR
Vendor

Theopaid

Products
8
CVEs
8
Across products
9
Status
Private

Products

8

Recent CVEs

8
  • CVE-2026-67617Aug 3, 2026
    risk 0.00cvss epss 0.00

    Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting malicious payloads via the tag_names parameter of the GET…

  • CVE-2026-67185Jul 28, 2026
    risk 0.00cvss epss 0.00

    TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting ../ sequences in the URL path, which are concatenated directly to the configured web root in HttpBuilder::buildResponse() without…

  • CVE-2026-67184Jul 28, 2026
    risk 0.00cvss epss 0.00

    TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to crash worker processes by sending a malformed HTTP request line with an invalid version string. The HttpParser::execute() function fails to allocate the Url…

  • CVE-2026-67183Jul 28, 2026
    risk 0.00cvss epss 0.00

    TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well-formed HTTP requests. Each request causes HttpParser::execute() to allocate Url objects, HttpHeaders objects, and HttpHeader…

  • CVE-2026-66751Jul 28, 2026
    risk 0.00cvss epss 0.00

    Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to archive any room on the server by sending a DELETE request to the rooms handler without ownership verification. Attackers can enumerate room IDs via the rooms…

  • CVE-2026-66750Jul 28, 2026
    risk 0.00cvss epss 0.00

    Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows authenticated attackers to download file attachments from private and password-protected rooms they are not a member of by exploiting missing room membership checks in the file retrieval…

  • CVE-2026-66730Jul 27, 2026
    risk 0.00cvss epss 0.01

    facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unauthenticated remote attacker to permanently freeze worker processes at 100% CPU by sending a multipart/form-data request with a partial closing boundary. The…

  • CVE-2026-66729Jul 27, 2026
    risk 0.00cvss epss 0.01

    facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauthenticated remote attackers to crash the server process by sending a crafted Content-Disposition header with an empty field name. Attackers can trigger a…