Trytond
Tryton · 9 CVEs
Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.4…
Nov 30, 2025
Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.…
Nov 30, 2025
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is…
Nov 30, 2025
An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x a…
Mar 7, 2022
An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x thro…
Mar 7, 2022
trytond 2.4: ModelView.button fails to validate authorization
Nov 21, 2019
In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10,…
Apr 5, 2019
model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 al…
Apr 13, 2016
model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict…
Jul 12, 2012
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-66424 | Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70. | MEDIUM | 0.24% | Nov 30, 2025 |
| CVE-2025-66423 | Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70. | HIGH | 0.23% | Nov 30, 2025 |
| CVE-2025-66422 | Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.… | MEDIUM | 0.29% | Nov 30, 2025 |
| CVE-2022-26661 | An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Appli… | MEDIUM | 1.41% | Mar 7, 2022 |
| CVE-2022-26662 | An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through… | HIGH | 1.97% | Mar 7, 2022 |
| CVE-2012-2238 | trytond 2.4: ModelView.button fails to validate authorization | HIGH | 1.78% | Nov 21, 2019 |
| CVE-2019-10868 | In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated u… | HIGH | 1.26% | Apr 5, 2019 |
| CVE-2015-0861 | model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypas… | MEDIUM | 1.16% | Apr 13, 2016 |
| CVE-2012-0215 | model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the rel… | HIGH | 1.98% | Jul 12, 2012 |
Showing 1 to 9 of 9 CVEs