Odoo records
56 published records for vendor odoo.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 28.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-284 Improper Access Control22
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-267 Privilege Defined With Unsafe Actions5
- CWE-732 Incorrect Permission Assignment for Critical Resource4
- CWE-20 Improper Input Validation4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
The weakness classes this vendor ships most often: where to look.
CWEAll records
56 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-10804No exploit | In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication underodoo · odoo · CWE-306 | Critical9.8 | — | 3.4% | Jul 4, 2017 |
40Plan | CVE-2018-14885No exploit | Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remoteodoo · odoo · CWE-284 | Critical9.8 | — | 2.2% | Jun 28, 2019 |
39Monitor | CVE-2023-48050No exploit | SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-attenodoo · biometric attendance · CWE-89 | Critical9.8 | — | 0.8% | Dec 14, 2023 |
37Monitor | CVE-2018-15640No exploit | Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated prodoo · odoo · CWE-284 | High8.8 | — | 7.8% | Apr 9, 2019 |
37Monitor | CVE-2018-14860No exploit | Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticatodoo · odoo · CWE-78 | Critical9.1 | — | 2.2% | Jul 3, 2019 |
36Monitor | CVE-2020-29396No exploit | A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows odoo · odoo · CWE-267 | High8.8 | — | 3.2% | Dec 22, 2020 |
36Monitor | CVE-2019-11781No exploit | Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackeodoo · odoo · CWE-20 | High8.8 | — | 2.1% | Dec 22, 2020 |
36Monitor | CVE-2018-15632No exploit | Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote odoo · odoo · CWE-20 | Critical9.1 | — | 1.2% | Dec 22, 2020 |
36Monitor | CVE-2021-44547No exploit | A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading todoo · odoo · CWE-267 | Critical9.1 | — | 0.7% | Apr 25, 2023 |
35Monitor | CVE-2017-10805No exploit | In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, incorrect access control on OAuth tokens in the odoo · odoo · CWE-863 | High8.8 | — | 1.0% | Jul 4, 2017 |
35Monitor | CVE-2024-12368No exploit | Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuthodoo · odoo · CWE-284 | High8.8 | — | 0.7% | Feb 25, 2025 |
34Monitor | CVE-2021-23166No exploit | A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and wodoo · odoo · CWE-267 | High8.7 | — | 0.6% | Apr 25, 2023 |
34Monitor | CVE-2021-23186No exploit | A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access andodoo · odoo · CWE-267 | High8.7 | — | 0.6% | Apr 25, 2023 |
33Monitor | CVE-2019-11780No exploit | Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authentodoo · odoo · CWE-284 | High8.1 | — | 2.1% | Dec 19, 2019 |
32Monitor | CVE-2018-14859No exploit | Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authodoo · odoo · CWE-284 | High8.1 | — | 1.0% | Jul 3, 2019 |
32Monitor | CVE-2018-14863No exploit | Incorrect access control in the RPC framework in Odoo Community 8.0 through 11.0 and Odoo Enterprise 9.0 through 11.0 allows authenticated uodoo · odoo · CWE-284 | High8.1 | — | 1.0% | Jul 3, 2019 |
32Monitor | CVE-2021-45111No exploit | Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to triggerodoo · odoo · CWE-284 | High8.1 | — | 0.8% | Apr 25, 2023 |
31Monitor | CVE-2018-14733No exploit | The Odoo Community Association (OCA) dbfilter_from_header module makes Odoo 8.x, 9.x, 10.x, and 11.x vulnerable to ReDoS (regular expressionodoo · odoo · CWE-20 | High7.5 | — | 2.2% | Jul 5, 2019 |
30Monitor | CVE-2021-23203No exploit | Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackodoo · odoo · CWE-284 | High7.5 | — | 0.9% | Apr 25, 2023 |
30Monitor | CVE-2021-23178No exploit | Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online paymentsodoo · odoo · CWE-284 | High7.5 | — | 0.6% | Apr 25, 2023 |
29Monitor | CVE-2024-34533No exploit | A SQL injection vulnerability in ZI PT Solusi Usaha Mudah Analytic Data Query module (aka izi_data) 11.0 through 17.x before 17.0.3 allows aCWE-89 | High7.3 | — | 0.5% | May 6, 2024 |
29Monitor | CVE-2024-34534No exploit | A SQL injection vulnerability in Cybrosys Techno Solutions Text Commander module (aka text_commander) 16.0 through 16.0.1 allows a remote atCWE-89 | High7.3 | — | 0.5% | May 6, 2024 |
28Monitor | CVE-2017-9416Proof of concept | Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local fiodoo · odoo · CWE-22 | Medium6.5 | — | 5.7% | Jun 4, 2017 |
27Monitor | CVE-2017-10803Proof of concept | In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Dodoo · odoo · CWE-502 | Medium6.5 | — | 3.6% | Jul 4, 2017 |
27Monitor | CVE-2018-14887No exploit | Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier odoo · odoo · CWE-20 | Medium6.5 | — | 1.8% | Jun 28, 2019 |
- CVE-2017-1080440Plan
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under
CriticalCVSS 9.8No exploitEPSS 3%odoo · odooJul 4, 2017
- CVE-2018-1488540Plan
Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote
CriticalCVSS 9.8No exploitEPSS 2%odoo · odooJun 28, 2019
- CVE-2023-4805039Monitor
SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-atten
CriticalCVSS 9.8No exploitEPSS 1%odoo · biometric attendanceDec 14, 2023
- CVE-2018-1564037Monitor
Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated pr
HighCVSS 8.8No exploitEPSS 8%odoo · odooApr 9, 2019
- CVE-2018-1486037Monitor
Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticat
CriticalCVSS 9.1No exploitEPSS 2%odoo · odooJul 3, 2019
- CVE-2020-2939636Monitor
A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows
HighCVSS 8.8No exploitEPSS 3%odoo · odooDec 22, 2020
- CVE-2019-1178136Monitor
Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attacke
HighCVSS 8.8No exploitEPSS 2%odoo · odooDec 22, 2020
- CVE-2018-1563236Monitor
Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote
CriticalCVSS 9.1No exploitEPSS 1%odoo · odooDec 22, 2020
- CVE-2021-4454736Monitor
A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading t
CriticalCVSS 9.1No exploitEPSS 1%odoo · odooApr 25, 2023
- CVE-2017-1080535Monitor
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, incorrect access control on OAuth tokens in the
HighCVSS 8.8No exploitEPSS 1%odoo · odooJul 4, 2017
- CVE-2024-1236835Monitor
Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth
HighCVSS 8.8No exploitEPSS 1%odoo · odooFeb 25, 2025
- CVE-2021-2316634Monitor
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and w
HighCVSS 8.7No exploitEPSS 1%odoo · odooApr 25, 2023
- CVE-2021-2318634Monitor
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access and
HighCVSS 8.7No exploitEPSS 1%odoo · odooApr 25, 2023
- CVE-2019-1178033Monitor
Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authent
HighCVSS 8.1No exploitEPSS 2%odoo · odooDec 19, 2019
- CVE-2018-1485932Monitor
Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows auth
HighCVSS 8.1No exploitEPSS 1%odoo · odooJul 3, 2019
- CVE-2018-1486332Monitor
Incorrect access control in the RPC framework in Odoo Community 8.0 through 11.0 and Odoo Enterprise 9.0 through 11.0 allows authenticated u
HighCVSS 8.1No exploitEPSS 1%odoo · odooJul 3, 2019
- CVE-2021-4511132Monitor
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger
HighCVSS 8.1No exploitEPSS 1%odoo · odooApr 25, 2023
- CVE-2018-1473331Monitor
The Odoo Community Association (OCA) dbfilter_from_header module makes Odoo 8.x, 9.x, 10.x, and 11.x vulnerable to ReDoS (regular expression
HighCVSS 7.5No exploitEPSS 2%odoo · odooJul 5, 2019
- CVE-2021-2320330Monitor
Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attack
HighCVSS 7.5No exploitEPSS 1%odoo · odooApr 25, 2023
- CVE-2021-2317830Monitor
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments
HighCVSS 7.5No exploitEPSS 1%odoo · odooApr 25, 2023
- CVE-2024-3453329Monitor
A SQL injection vulnerability in ZI PT Solusi Usaha Mudah Analytic Data Query module (aka izi_data) 11.0 through 17.x before 17.0.3 allows a
HighCVSS 7.3No exploitEPSS 1%May 6, 2024
- CVE-2024-3453429Monitor
A SQL injection vulnerability in Cybrosys Techno Solutions Text Commander module (aka text_commander) 16.0 through 16.0.1 allows a remote at
HighCVSS 7.3No exploitEPSS 0%May 6, 2024
- CVE-2017-941628Monitor
Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local fi
MediumCVSS 6.5Proof of conceptEPSS 6%odoo · odooJun 4, 2017
- CVE-2017-1080327Monitor
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the D
MediumCVSS 6.5Proof of conceptEPSS 4%odoo · odooJul 4, 2017
- CVE-2018-1488727Monitor
Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier
MediumCVSS 6.5No exploitEPSS 2%odoo · odooJun 28, 2019