← Back

Petereport

petereport

Vendor: Petereport Project • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Petereport Project
1Petereport
Jun 17, 2026
Mar 3, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code inside the markdown descriptions while creating a product, report or finding.
1Petereport Project
1Petereport
Jun 17, 2026
Mar 3, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
PeteReport Version 0.5 contains a Cross Site Request Forgery (CSRF) vulnerability allowing an attacker to trick users into deleting users, products, reports and findings on the application.
1Petereport Project
1Petereport
Jun 17, 2026
Mar 3, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code while adding an 'Attack Tree' by modifying the 'svg_file' parameter.