Home/Product/jorani
Product

jorani

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-67102
<= 1.0.4
A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to execute arbitr
7.6HIGH
CVE-2023-48205
all versions
Jorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emails.
5.3MEDIUM
CVE-2023-45540
all versions
An issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted script to t
6.5MEDIUM
CVE-2023-2681
all versions
An SQL Injection vulnerability has been found on Jorani version 1.0.0. This vulnerability allows an authenticated remote user, wit
8.8HIGH
CVE-2023-26469
all versions
In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.
9.8CRITICAL
CVE-2022-48118
all versions
Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Acronym parameter.
6.1MEDIUM
CVE-2022-34134
all versions
Jorani v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /application/controllers/Users.php.
8.8HIGH
CVE-2022-34133
all versions
Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Comment parameter at application/controll
6.1MEDIUM
CVE-2022-34132
all versions
Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leaves.php.
9.8CRITICAL
CVE-2018-15918
all versions
An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read
5.4MEDIUM
CVE-2018-15917
all versions
Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the
5.4MEDIUM
threatengine.sh