VulnSea

syslifters has 6 CVEs on record between 2025 and 2026. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 6.2 (medium). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
6.2
Publish → KEV
—
Last 90 days
5 prev 0

Products

  • sysreptor 6
6
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

syslifters vulnerabilities

CVEs affecting syslifters, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-81182Medium· 4.2
3w ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a public read-write note share link can disclose an uploaded file or image from the same project by updating the shared…

▾ SunlitSyslifters · sysreptorEPSS 0.27%via NVD
CVE-2026-81181Low· 3.7
3w ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for protected shared notes does not rotate the session identifier after successful authentication, allowing session fixation…

▾ SunlitSyslifters · sysreptorEPSS 0.28%via NVD
CVE-2026-81180High· 8.8
3w ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript…

▾ TwilightSyslifters · sysreptorEPSS 0.66%via NVD
CVE-2026-81179High· 8.1
3w ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header when generating a…

▾ TwilightSyslifters · sysreptorEPSS 0.48%via NVD
CVE-2026-81178Low· 3.5
3w ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public note share link receives project-wide collaborative editing metadata because the public share consumer joins the same c…

▾ SunlitSyslifters · sysreptorEPSS 0.30%via NVD
CVE-2025-59945High· 8.1
1y ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated and unprivileged (non-admin) users can assign the is_project_admin permission to their own user. This allows users to…

▾ Twilightsyslifters · sysreptorEPSS 0.33%via NVD
syslifters vulnerabilities (CVEs) · VulnSea