VYPR
Vendor

Webreinvent

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2025-61183MedOct 8, 2025
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting in vaahcms v.2.3.1 allows a remote attacker to execute arbitrary code via upload method in the storeAvatar() method of UserBase.php

  • CVE-2026-67595Jul 29, 2026
    risk 0.00cvss epss 0.00

    VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template…