Syslifters has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 4.2 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.2
- Publish → KEV
- —
- Last 90 days
- 5 prev 0
Worst active — by depth score
CVE-2026-81180High· 8.8SysReptor is a fully customizable pentest reporting platform48CVE-2026-81179High· 8.1SysReptor is a fully customizable pentest reporting platform45CVE-2026-81182Medium· 4.2SysReptor is a fully customizable pentest reporting platform23CVE-2026-81181Low· 3.7SysReptor is a fully customizable pentest reporting platform20CVE-2026-81178Low· 3.5SysReptor is a fully customizable pentest reporting platform19
Syslifters vulnerabilities
CVEs affecting Syslifters, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-81182Medium· 4.2SysReptor is a fully customizable pentest reporting platform
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a public read-write note share link can disclose an uploaded file or image from the same project by updating the shared…
CVE-2026-81181Low· 3.7SysReptor is a fully customizable pentest reporting platform
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for protected shared notes does not rotate the session identifier after successful authentication, allowing session fixation…
CVE-2026-81180High· 8.8SysReptor is a fully customizable pentest reporting platform
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript…
CVE-2026-81179High· 8.1SysReptor is a fully customizable pentest reporting platform
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header when generating a…
CVE-2026-81178Low· 3.5SysReptor is a fully customizable pentest reporting platform
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public note share link receives project-wide collaborative editing metadata because the public share consumer joins the same c…