Vulnerabilities in baptisteArno
34 resultsVexday analysis
O fornecedor baptisteArno apresenta 19 vulnerabilidades catalogadas, com 15 publicadas nos últimos 90 dias, indicando atividade recente significativa na superfície de exposição. Embora nenhuma vulnerabilidade esteja sob ataque ativo no momento, 3 são classificadas como críticas e a fraqueza dominante (CWE-639: autorização inadequada) representa um vetor de risco estrutural que demanda revisão de controles de acesso. O volume concentrado em janela recente sugere acompanhamento contínuo para identificar possíveis exploração futura.
CVE-2025-64709CRITICALTypebot May Expose AWS EKS Credentials via Server Side Request Forgery in Webhook BlockEPSS 0.4%CVE-2026-39965HIGHTypeBot: SSRF via Open Redirect Bypass in HTTP Request and Code BlocksEPSS 0.4%CVE-2026-42142HIGHTypeBot has Authorization Bypass in Google Sheets `getSheets` Endpoint that Allows Cross-Workspace Credential AccessEPSS 0.4%CVE-2026-48759HIGHTypeBot: Cross-Workspace Theme Template IDOR (Modification and Deletion)EPSS 0.4%CVE-2026-48495HIGHTypeBot Google Sheets OAuth callback can create credentials in unauthorized workspaces and modify arbitrary typebotsEPSS 0.4%CVE-2025-65098HIGHTypebot Vulnerable to Credential Theft via Client-Side Script Execution and API Authorization BypassEPSS 0.3%CVE-2026-39964MEDIUMTypeBot: Stored XSS via javascript: URI in text bubble links — bot author executes JS on visitors' browsersEPSS 0.3%CVE-2026-48483MEDIUMTypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF from the Typebot serverEPSS 0.3%CVE-2026-62865HIGHTypeBot: Arbitrary server file read via Send Email block attachment pathEPSS 0.3%CVE-2026-48762MEDIUMTypeBot Vulnerable to Server-Side Request Forgery (SSRF) in OpenAI Transcription HandlerEPSS 0.3%CVE-2026-47702CRITICALTypeBot API tokens stored in plaintextEPSS 0.3%CVE-2026-39967LOWTypeBot: Cross-Typebot Result Data Access via Missing typebotId FilterEPSS 0.3%CVE-2025-64706MEDIUMTypebot IDOR Vulnerability: Unauthorized API Token Deletion and ExposureEPSS 0.2%CVE-2026-39969MEDIUMTypeBot: WhatsApp Webhook Endpoint Missing Signature VerificationEPSS 0.2%