CVE-2025-59945High· 8.1▾ TwilightSysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated and unprivileged (non-admin) users can assign the is_project_admin permission to their own user. This allows users to…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
SysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated and unprivileged (non-admin) users can assign the is_project_admin permission to their own user. This allows users to read, modify and delete pentesting projects they are not members of and are therefore not supposed to access. This issue has been patched in version 2025.83.
sysreptor >= 2024.74, < 2025.83Upgrade past the affected range:
sysreptor 2025.83Connected by shared product, vendor, weakness, or advisory.
CVE-2026-81182Medium· 4.2SysReptor is a fully customizable pentest reporting platform
CVE-2026-81180High· 8.8SysReptor is a fully customizable pentest reporting platform
CVE-2026-81181Low· 3.7SysReptor is a fully customizable pentest reporting platform
CVE-2026-81178Low· 3.5SysReptor is a fully customizable pentest reporting platform
CVE-2026-81179High· 8.1SysReptor is a fully customizable pentest reporting platform
CVE-2025-11050Medium· 6.3A flaw has been found in Portabilis i-Educar up to 2.10