Product
weberp
12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2020-37082
CVE-2025-46053
CVE-2025-46052
CVE-2015-10018
CVE-2020-22474
CVE-2019-7755
CVE-2019-13292
CVE-2018-20420
CVE-2018-19436
CVE-2018-19435
CVE-2018-19434
CVE-2003-1383
all versions
webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database backup files
all versions
A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive data by i
all versions
An error-based SQL Injection (SQLi) vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL command and extract
< 1.0.0
A vulnerability has been found in DBRisinajumi d2files and classified as critical. Affected by this vulnerability is the function
all versions
In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local file inclusi
all versions
In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, result
all versions
A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it
all versions
In webERP 4.15, Z_CreateCompanyTemplateFile.php has Incorrect Access Control, leading to the overwrite of an existing .sql file on
all versions
An issue was discovered in the Manufacturing component in webERP 4.15. CollectiveWorkOrderCost.php has Blind SQL Injection via the
all versions
An issue was discovered in the Sales component in webERP 4.15. SalesInquiry.php has SQL Injection via the SortBy parameter.
all versions
An issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15. BankMatch
<= 0.1.4
WEB-ERP 0.1.4 and earlier allows remote attackers to obtain sensitive information via an HTTP request for the logicworks.ini file,