LogicalDOC / Logicaldoc
19 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2019-25258 | LogicalDOC Enterprise 7.7.4 Multiple Post-Authentication Directory Traversal Vulnerabilities | HIGH | 7.1 | Dec 24, 2025 |
| CVE-2025-12547 | LogicalDOC Community Edition Admin Login login.jsp excessive authentication | MEDIUM | 6.3 | Oct 31, 2025 |
| CVE-2025-12546 | LogicalDOC Community Edition API Key creation UI cross site scripting | MEDIUM | 5.1 | Oct 31, 2025 |
| CVE-2025-11946 | LogicalDOC Community Edition Add Contact frontend.jsp cross site scripting | MEDIUM | 5.1 | Oct 19, 2025 |
| CVE-2024-12020 | Reflected Cross-Site Scripting (XSS) | MEDIUM | 6.4 | Mar 14, 2025 |
| CVE-2024-54449 | Remote Code Execution (RCE) via Arbitrary File Write In Document API | HIGH | 8.7 | Mar 14, 2025 |
| CVE-2024-54448 | Remote Code Execution (RCE) via Automation Scripting | HIGH | 8.6 | Mar 14, 2025 |
| CVE-2022-47418 | LogicalDOC Document Version Comment Stored XSS | MEDIUM | 5.4 | Feb 7, 2023 |
| CVE-2022-47417 | LogicalDOC Document File Name Stored XSS | MEDIUM | 5.4 | Feb 7, 2023 |
| CVE-2022-47416 | LogicalDOC Chat Stored XSS | MEDIUM | 5.4 | Feb 7, 2023 |
| CVE-2022-47415 | LogicalDOC Messaging Stored XSS | MEDIUM | 5.4 | Feb 7, 2023 |
| CVE-2020-13542 | A local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation. Depending on the vector chosen, an attacker c… | HIGH | 7.8 | Dec 3, 2020 |
| CVE-2020-10366 | LogicalDoc before 8.3.3 allows /servlet.gupld Directory Traversal, a different vulnerability than CVE-2020-9423 and CVE-2020-10365. | HIGH | 7.5 | Apr 7, 2020 |
| CVE-2020-10365 | LogicalDoc before 8.3.3 allows SQL Injection. LogicalDoc populates the list of available documents by querying the database. This list could be filtered by mod… | MEDIUM | 6.5 | Mar 18, 2020 |
| CVE-2020-9423 | LogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of data from the database. LogicalDoc prov… | CRITICAL | 9.8 | Mar 18, 2020 |
| CVE-2019-9723 | LogicalDOC Community Edition 8.x before 8.2.1 has a path traversal vulnerability that allows reading arbitrary files and the creation of directories, in the cl… | HIGH | 7.1 | May 30, 2019 |
| CVE-2017-1000023 | LogicalDoc Community Edition 7.5.3 and prior is vulnerable to an XSS when using preview on HTML document. | MEDIUM | 5.4 | Jul 13, 2017 |
| CVE-2017-1000022 | LogicalDoc Community Edition 7.5.3 and prior contain an Incorrect access control which could leave to privilege escalation. | HIGH | 8.8 | Jul 13, 2017 |
| CVE-2017-1000021 | LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents. | HIGH | 8.8 | Jul 13, 2017 |
Showing 1 to 19 of 19 CVEs