Syslifters
Syslifters Sysreptor: vulnerabilidades y CVE
Syslifters Sysreptor tiene 10 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses8
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-81182 | Media (4.2) | 0.27% | — | 18 sept 2026 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a public read-write note share link can disclose an uploaded file or image from the same project by… |
| CVE-2026-81181 | Baja (3.7) | 0.28% | — | 18 sept 2026 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for protected shared notes does not rotate the session identifier after successful authentication,… |
| CVE-2026-81180 | Alta (8.8) | 0.66% | — | 18 sept 2026 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing… |
| CVE-2026-81179 | Alta (8.1) | 0.48% | — | 18 sept 2026 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header… |
| CVE-2026-81178 | Baja (3.5) | 0.30% | — | 18 sept 2026 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public note share link receives project-wide collaborative editing metadata because the public share… |
| CVE-2026-44987 | Baja (3.8) | 0.27% | — | 8 may 2026 | SysReptor is a fully customizable pentest reporting platform. Prior to version 2026.29, users with "User Admin" permissions can change the email addresses of users with "Superuser" permissions. If the SysReptor… |
| CVE-2026-42291 | Media (6.8) | 0.31% | — | 8 may 2026 | SysReptor is a fully customizable pentest reporting platform. From version 2026.4 to before version 2026.27, the endpoints for reading and creating sharing links for personal notes is not properly authorized. This… |
| CVE-2025-66561 | Media (5.4) | 0.19% | — | 4 dic 2025 | SysReptor is a fully customizable pentest reporting platform. Prior to 2025.102, there is a Stored Cross-Site Scripting (XSS) vulnerability allows authenticated users to execute malicious JavaScript in the context of… |
| CVE-2025-59945 | Alta (8.1) | 0.33% | — | 27 sept 2025 | SysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated and unprivileged (non-admin) users can assign the is_project_admin permission to their own user.… |
| CVE-2024-36076 | Alta (8.8) | 0.25% | — | 19 may 2024 | Cross-Site WebSocket Hijacking in SysReptor from version 2024.28 to version 2024.30 causes attackers to escalate privileges and obtain sensitive information when a logged-in SysReptor user visits a malicious same-site… |