Export limit exceeded: 334967 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (3 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2019-25312 | 1 Inoideas | 1 Inoerp | 2026-02-11 | 6.4 Medium |
| InoERP 0.7.2 contains a persistent cross-site scripting vulnerability in the comment section that allows unauthenticated attackers to inject malicious scripts. Attackers can submit comments with JavaScript payloads that execute in other users' browsers, potentially stealing cookies and session information. | ||||
| CVE-2020-28870 | 1 Inoideas | 1 Inoerp | 2024-11-21 | 9.8 Critical |
| In InoERP 0.7.2, an unauthorized attacker can execute arbitrary code on the server side due to lack of validations in /modules/sys/form_personalization/json_fp.php. | ||||
| CVE-2019-16894 | 1 Inoideas | 1 Inoerp | 2024-11-21 | 9.8 Critical |
| download.php in inoERP 4.15 allows SQL injection through insecure deserialization. | ||||
Page 1 of 1.