Tryton / Trytond
9 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-66424 | Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70. | MEDIUM | 6.5 | Nov 30, 2025 |
| CVE-2025-66423 | Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70. | HIGH | 7.1 | Nov 30, 2025 |
| CVE-2025-66422 | Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.… | MEDIUM | 4.3 | Nov 30, 2025 |
| CVE-2022-26661 | An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Appli… | MEDIUM | 6.5 | Mar 7, 2022 |
| CVE-2022-26662 | An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through… | HIGH | 7.5 | Mar 7, 2022 |
| CVE-2012-2238 | trytond 2.4: ModelView.button fails to validate authorization | HIGH | 8.7 | Nov 21, 2019 |
| CVE-2019-10868 | In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated u… | HIGH | 7.1 | Apr 5, 2019 |
| CVE-2015-0861 | model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypas… | MEDIUM | 5.3 | Apr 13, 2016 |
| CVE-2012-0215 | model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the rel… | HIGH | 7.1 | Jul 12, 2012 |
Showing 1 to 9 of 9 CVEs