LogicalDOC records
19 published records for vendor logicaldoc.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-276 Incorrect Default Permissions1
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-611 Improper Restriction of XML External Entity Reference1
The weakness classes this vendor ships most often: where to look.
CWEAll records
19 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2020-9423No exploit | LogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of data from the databalogicaldoc · logicaldoc · CWE-434 | Critical9.8 | — | 5.0% | Mar 18, 2020 |
35Monitor | CVE-2017-1000022No exploit | LogicalDoc Community Edition 7.5.3 and prior contain an Incorrect access control which could leave to privilege escalation.logicaldoc · logicaldoc · CWE-732 | High8.8 | — | 1.2% | Jul 17, 2017 |
35Monitor | CVE-2017-1000021No exploit | LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.logicaldoc · logicaldoc · CWE-611 | High8.8 | — | 1.2% | Jul 17, 2017 |
34Monitor | CVE-2024-54449No exploit | Remote Code Execution (RCE) via Arbitrary File Write In Document APIlogicaldoc · logicaldoc · CWE-23 | High8.7 | — | 0.6% | Mar 14, 2025 |
34Monitor | CVE-2024-54448No exploit | Remote Code Execution (RCE) via Automation Scriptinglogicaldoc · logicaldoc · CWE-94 | High8.6 | — | 0.6% | Mar 14, 2025 |
31Monitor | CVE-2020-13542No exploit | A local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation.logicaldoc · logicaldoc · CWE-276 | High7.8 | — | 0.6% | Dec 3, 2020 |
30Monitor | CVE-2020-10366No exploit | LogicalDoc before 8.3.3 allows /servlet.gupld Directory Traversal, a different vulnerability than CVE-2020-9423 and CVE-2020-10365.logicaldoc · logicaldoc · CWE-22 | High7.5 | — | 1.5% | Apr 7, 2020 |
28Monitor | CVE-2019-9723No exploit | LogicalDOC Community Edition 8.x before 8.2.1 has a path traversal vulnerability that allows reading arbitrary files and the creation of dirlogicaldoc · logicaldoc · CWE-22 | High7.1 | — | 1.3% | May 30, 2019 |
28Monitor | CVE-2019-25258No exploit | LogicalDOC Enterprise 7.7.4 Multiple Post-Authentication Directory Traversal Vulnerabilitieslogicaldoc · logicaldoc · CWE-22 | High7.1 | — | 1.1% | Dec 24, 2025 |
26Monitor | CVE-2020-10365No exploit | LogicalDoc before 8.3.3 allows SQL Injection.logicaldoc · logicaldoc · CWE-89 | Medium6.5 | — | 1.3% | Mar 18, 2020 |
25Monitor | CVE-2024-12020No exploit | Reflected Cross-Site Scripting (XSS)logicaldoc · logicaldoc · CWE-79 | Medium6.4 | — | 0.3% | Mar 14, 2025 |
21Monitor | CVE-2017-1000023No exploit | LogicalDoc Community Edition 7.5.3 and prior is vulnerable to an XSS when using preview on HTML document.logicaldoc · logicaldoc · CWE-79 | Medium5.4 | — | 0.5% | Jul 17, 2017 |
21Monitor | CVE-2022-47418No exploit | LogicalDOC Document Version Comment Stored XSSlogicaldoc · logicaldoc · CWE-79 | Medium5.4 | — | 0.5% | Feb 7, 2023 |
21Monitor | CVE-2022-47417No exploit | LogicalDOC Document File Name Stored XSSlogicaldoc · logicaldoc · CWE-79 | Medium5.4 | — | 0.5% | Feb 7, 2023 |
21Monitor | CVE-2022-47416No exploit | LogicalDOC Chat Stored XSSlogicaldoc · logicaldoc · CWE-79 | Medium5.4 | — | 0.5% | Feb 7, 2023 |
21Monitor | CVE-2022-47415No exploit | LogicalDOC Messaging Stored XSSlogicaldoc · logicaldoc · CWE-79 | Medium5.4 | — | 0.5% | Feb 7, 2023 |
11Monitor | CVE-2025-12547No exploit | LogicalDOC Community Edition Admin Login login.jsp excessive authenticationlogicaldoc · logicaldoc · CWE-307 | Low2.9 | — | 0.8% | Oct 31, 2025 |
8Monitor | CVE-2025-11946No exploit | LogicalDOC Community Edition Add Contact frontend.jsp cross site scriptinglogicaldoc · logicaldoc · CWE-79 | Low2.0 | — | 0.4% | Oct 19, 2025 |
8Monitor | CVE-2025-12546No exploit | LogicalDOC Community Edition API Key creation UI cross site scriptinglogicaldoc · logicaldoc · CWE-79 | Low2.0 | — | 0.3% | Oct 31, 2025 |
- CVE-2020-942341Plan
LogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of data from the databa
CriticalCVSS 9.8No exploitEPSS 5%logicaldoc · logicaldocMar 18, 2020
- CVE-2017-100002235Monitor
LogicalDoc Community Edition 7.5.3 and prior contain an Incorrect access control which could leave to privilege escalation.
HighCVSS 8.8No exploitEPSS 1%logicaldoc · logicaldocJul 17, 2017
- CVE-2017-100002135Monitor
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.
HighCVSS 8.8No exploitEPSS 1%logicaldoc · logicaldocJul 17, 2017
- CVE-2024-5444934Monitor
Remote Code Execution (RCE) via Arbitrary File Write In Document API
HighCVSS 8.7No exploitEPSS 1%logicaldoc · logicaldocMar 14, 2025
- CVE-2024-5444834Monitor
Remote Code Execution (RCE) via Automation Scripting
HighCVSS 8.6No exploitEPSS 1%logicaldoc · logicaldocMar 14, 2025
- CVE-2020-1354231Monitor
A local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation.
HighCVSS 7.8No exploitEPSS 1%logicaldoc · logicaldocDec 3, 2020
- CVE-2020-1036630Monitor
LogicalDoc before 8.3.3 allows /servlet.gupld Directory Traversal, a different vulnerability than CVE-2020-9423 and CVE-2020-10365.
HighCVSS 7.5No exploitEPSS 1%logicaldoc · logicaldocApr 7, 2020
- CVE-2019-972328Monitor
LogicalDOC Community Edition 8.x before 8.2.1 has a path traversal vulnerability that allows reading arbitrary files and the creation of dir
HighCVSS 7.1No exploitEPSS 1%logicaldoc · logicaldocMay 30, 2019
- CVE-2019-2525828Monitor
LogicalDOC Enterprise 7.7.4 Multiple Post-Authentication Directory Traversal Vulnerabilities
HighCVSS 7.1No exploitEPSS 1%logicaldoc · logicaldocDec 24, 2025
- CVE-2020-1036526Monitor
LogicalDoc before 8.3.3 allows SQL Injection.
MediumCVSS 6.5No exploitEPSS 1%logicaldoc · logicaldocMar 18, 2020
- CVE-2024-1202025Monitor
Reflected Cross-Site Scripting (XSS)
MediumCVSS 6.4No exploitEPSS 0%logicaldoc · logicaldocMar 14, 2025
- CVE-2017-100002321Monitor
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to an XSS when using preview on HTML document.
MediumCVSS 5.4No exploitEPSS 1%logicaldoc · logicaldocJul 17, 2017
- CVE-2022-4741821Monitor
LogicalDOC Document Version Comment Stored XSS
MediumCVSS 5.4No exploitEPSS 0%logicaldoc · logicaldocFeb 7, 2023
- CVE-2022-4741721Monitor
LogicalDOC Document File Name Stored XSS
MediumCVSS 5.4No exploitEPSS 0%logicaldoc · logicaldocFeb 7, 2023
- CVE-2022-4741621Monitor
LogicalDOC Chat Stored XSS
MediumCVSS 5.4No exploitEPSS 0%logicaldoc · logicaldocFeb 7, 2023
- CVE-2022-4741521Monitor
LogicalDOC Messaging Stored XSS
MediumCVSS 5.4No exploitEPSS 0%logicaldoc · logicaldocFeb 7, 2023
- CVE-2025-1254711Monitor
LogicalDOC Community Edition Admin Login login.jsp excessive authentication
LowCVSS 2.9No exploitEPSS 1%logicaldoc · logicaldocOct 31, 2025
- CVE-2025-119468Monitor
LogicalDOC Community Edition Add Contact frontend.jsp cross site scripting
LowCVSS 2.0No exploitEPSS 0%logicaldoc · logicaldocOct 19, 2025
- CVE-2025-125468Monitor
LogicalDOC Community Edition API Key creation UI cross site scripting
LowCVSS 2.0No exploitEPSS 0%logicaldoc · logicaldocOct 31, 2025