threat
engine
.sh
Back
·
··:··
Home
/
Product
/
tryton trytond
Product
tryton trytond
9 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2025-66424
>= 6.0.0 and < 6.0.70
Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.
6.5
MEDIUM
CVE-2025-66423
>= 6.0.0 and < 6.0.70
Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21,
7.1
HIGH
CVE-2025-66422
>= 6.0.0 and < 6.0.70
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7
4.3
MEDIUM
CVE-2022-26662
>= 5.0.0 and < 5.0.46
An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15,
7.5
HIGH
CVE-2022-26661
>= 5.0.0 and < 5.0.46
An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x th
6.5
MEDIUM
CVE-2012-2238
>= 2.4.0 and < 2.4.2
trytond 2.4: ModelView.button fails to validate authorization
7.5
HIGH
CVE-2019-10868
>= 4.2.0 and < 4.2.21
In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 bef
6.5
MEDIUM
CVE-2015-0861
>= 3.2.0 and < 3.2.10
model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote
4.3
MEDIUM
CVE-2012-0215
<= 2.2.3
model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to t
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin