Syslifters develops Sysreptor, a penetration-testing and security-assessment platform, with its vulnerability profile centered on web-application security weaknesses including cross-site request forgery, cross-site scripting, and improper privilege assignment. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Syslifters over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-59945HIGH SysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated and unprivileged (non-admin) users can assign the is_project | Sep 27, 2025 | 8.1 | 28 | NO | NO |
CVE-2024-36076HIGH Cross-Site WebSocket Hijacking in SysReptor from version 2024.28 to version 2024.30 causes attackers to escalate privileges and obtain sensitive information when a logged-in SysRep | May 19, 2024 | 8.8 | 24 | NO | NO |
CVE-2025-66561MEDIUM SysReptor is a fully customizable pentest reporting platform. Prior to 2025.102, there is a Stored Cross-Site Scripting (XSS) vulnerability allows authenticated users to execute ma | Dec 4, 2025 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Syslifters.
Media articles that mention a CVE ID that affects a product developed by Syslifters — matched by CVE ID, not by vendor name.