CVE-2015-5632: Newphoria Corporation Applican

Medium severity, CVSS 6.8. EPSS: 1.1% chance of exploitation in the next 30 days.

The runtime engine in the Newphoria applican framework before 1.12.3 for Android and before 1.12.2 for iOS allows attackers to bypass a whitelist.xml URL whitelist protection mechanism and obtain API access via unspecified vectors.

Affected products

Published 2015-09-20. Last modified 2026-06-17.