VulnSea

sysreptor vulnerabilities

CVEs whose affected-version data names the sysreptor package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-81182Medium· 4.2
4d ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a public read-write note share link can disclose an uploaded file or image from the same project by updating the shared…

SunlitSyslifters · sysreptorEPSS 0.17%via NVD
CVE-2026-81181Low· 3.7
4d ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for protected shared notes does not rotate the session identifier after successful authentication, allowing session fixation…

SunlitSyslifters · sysreptorEPSS 0.22%via NVD
CVE-2026-81180High· 8.8
4d ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript…

TwilightSyslifters · sysreptorEPSS 0.36%via NVD
CVE-2026-81179High· 8.1
4d ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header when generating a…

TwilightSyslifters · sysreptorEPSS 0.26%via NVD
CVE-2026-81178Low· 3.5
4d ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public note share link receives project-wide collaborative editing metadata because the public share consumer joins the same c…

SunlitSyslifters · sysreptorEPSS 0.21%via NVD
sysreptor vulnerabilities (CVEs) · VulnSea