Tryton records
15 published records for vendor tryton.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-863 Incorrect Authorization3
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-269 Improper Privilege Management1
- CWE-384 Session Fixation1
- CWE-402 Transmission of Private Resources into a New Sphere ('Resource Leak')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2014-6633No exploit | The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7, and 3.2.x before 3.tryton · tryton · CWE-77 | High8.8 | — | 2.6% | Apr 12, 2018 |
32Monitor | CVE-2013-4510No exploit | Directory traversal vulnerability in the client in Tryton 3.0.0, as distributed before 20131104 and earlier, allows remote servers to write tryton · tryton · CWE-22 | High7.8 | — | 2.2% | Nov 17, 2013 |
31Monitor | CVE-2022-26662No exploit | An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.xtryton · proteus · CWE-776 | High7.5 | — | 2.0% | Mar 10, 2022 |
31Monitor | CVE-2012-2238No exploit | trytond 2.4: ModelView.button fails to validate authorizationtryton · trytond · CWE-863 | High7.5 | — | 1.8% | Nov 21, 2019 |
28Monitor | CVE-2025-66423No exploit | Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor.tryton · trytond · CWE-863 | High7.1 | — | 0.2% | Nov 29, 2025 |
26Monitor | CVE-2022-26661No exploit | An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.tryton · proteus · CWE-611 | Medium6.5 | — | 1.4% | Mar 10, 2022 |
26Monitor | CVE-2019-10868No exploit | In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6,tryton · trytond · CWE-862 | Medium6.5 | — | 1.3% | Apr 4, 2019 |
26Monitor | CVE-2025-66424No exploit | Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export.tryton · trytond · CWE-863 | Medium6.5 | — | 0.2% | Nov 29, 2025 |
23Monitor | CVE-2012-0215No exploit | model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Matryton · trytond · CWE-264 | Medium5.5 | — | 2.0% | Jul 12, 2012 |
23Monitor | CVE-2018-19443No exploit | The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under certain circumstances intryton · tryton · CWE-384 | Medium5.9 | — | 1.1% | Nov 22, 2018 |
21Monitor | CVE-2016-1241No exploit | Tryton 3.x before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allow remote authenticated usertryton · tryton · CWE-200 | Medium5.3 | — | 1.6% | Sep 7, 2016 |
21Monitor | CVE-2017-0360No exploit | file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "sametryton · tryton · CWE-269 | Medium5.3 | — | 1.6% | Apr 4, 2017 |
18Monitor | CVE-2016-1242No exploit | file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authentitryton · tryton · CWE-200 | Medium4.4 | — | 1.8% | Sep 7, 2016 |
17Monitor | CVE-2015-0861No exploit | model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authentictryton · trytond · CWE-264 | Medium4.3 | — | 1.2% | Apr 13, 2016 |
17Monitor | CVE-2025-66422No exploit | Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information.tryton · trytond · CWE-402 | Medium4.3 | — | 0.3% | Nov 29, 2025 |
- CVE-2014-663336Monitor
The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7, and 3.2.x before 3.
HighCVSS 8.8No exploitEPSS 3%tryton · trytonApr 12, 2018
- CVE-2013-451032Monitor
Directory traversal vulnerability in the client in Tryton 3.0.0, as distributed before 20131104 and earlier, allows remote servers to write
HighCVSS 7.8No exploitEPSS 2%tryton · trytonNov 17, 2013
- CVE-2022-2666231Monitor
An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x
HighCVSS 7.5No exploitEPSS 2%tryton · proteusMar 10, 2022
- CVE-2012-223831Monitor
trytond 2.4: ModelView.button fails to validate authorization
HighCVSS 7.5No exploitEPSS 2%tryton · trytondNov 21, 2019
- CVE-2025-6642328Monitor
Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor.
HighCVSS 7.1No exploitEPSS 0%tryton · trytondNov 29, 2025
- CVE-2022-2666126Monitor
An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.
MediumCVSS 6.5No exploitEPSS 1%tryton · proteusMar 10, 2022
- CVE-2019-1086826Monitor
In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6,
MediumCVSS 6.5No exploitEPSS 1%tryton · trytondApr 4, 2019
- CVE-2025-6642426Monitor
Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export.
MediumCVSS 6.5No exploitEPSS 0%tryton · trytondNov 29, 2025
- CVE-2012-021523Monitor
model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Ma
MediumCVSS 5.5No exploitEPSS 2%tryton · trytondJul 12, 2012
- CVE-2018-1944323Monitor
The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under certain circumstances in
MediumCVSS 5.9No exploitEPSS 1%tryton · trytonNov 22, 2018
- CVE-2016-124121Monitor
Tryton 3.x before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allow remote authenticated user
MediumCVSS 5.3No exploitEPSS 2%tryton · trytonSep 7, 2016
- CVE-2017-036021Monitor
file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "same
MediumCVSS 5.3No exploitEPSS 2%tryton · trytonApr 4, 2017
- CVE-2016-124218Monitor
file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authenti
MediumCVSS 4.4No exploitEPSS 2%tryton · trytonSep 7, 2016
- CVE-2015-086117Monitor
model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authentic
MediumCVSS 4.3No exploitEPSS 1%tryton · trytondApr 13, 2016
- CVE-2025-6642217Monitor
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information.
MediumCVSS 4.3No exploitEPSS 0%tryton · trytondNov 29, 2025