Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
14025.0%HIGH

Related CVEs

4
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2025-25478The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web application s source code, exposing sensitive information such as the database password.MEDIUM6.531.6%Feb 28, 2025
CVE-2025-25476A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javascript code by specifying a malicious XSS payload as a notification type or notification component.MEDIUM5.414.4%Feb 28, 2025
CVE-2025-25477A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.HIGH8.130.7%Feb 28, 2025
CVE-2024-42904A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name parameter at /Controllers/ClientController.php.MEDIUM6.123.2%Sep 3, 2024