Jhpyle maintains docassemble, a document-assembly and legal-automation platform whose vulnerability profile centers on web-application input handling and trust management, with recurring issues in cross-site scripting, open redirects, and name-resolution weaknesses. Treat this as a compact vendor footprint; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jhpyle over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-27292HIGH Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through URL | Mar 21, 2024 | 7.5 | 74 | NO | YES |
CVE-2024-27291MEDIUM Docassemble is an expert system for guided interviews and document assembly. Prior to 1.4.97, it is possible to create a URL that acts as an open redirect. The vulnerability has be | Mar 21, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-27290MEDIUM Docassemble is an expert system for guided interviews and document assembly. Prior to 1.4.97, a user could type HTML into a field, including the field for the user's name, and then | Mar 21, 2024 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jhpyle.
Media articles that mention a CVE ID that affects a product developed by Jhpyle — matched by CVE ID, not by vendor name.