Skip to content
Noroxi

Tryton records

15 published records for vendor tryton.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

15 records
  • CVE-2014-6633
    36Monitor

    The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7, and 3.2.x before 3.

    HighCVSS 8.8No exploitEPSS 3%

    tryton · trytonApr 12, 2018

  • CVE-2013-4510
    32Monitor

    Directory traversal vulnerability in the client in Tryton 3.0.0, as distributed before 20131104 and earlier, allows remote servers to write

    HighCVSS 7.8No exploitEPSS 2%

    tryton · trytonNov 17, 2013

  • An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x

    HighCVSS 7.5No exploitEPSS 2%

    tryton · proteusMar 10, 2022

  • CVE-2012-2238
    31Monitor

    trytond 2.4: ModelView.button fails to validate authorization

    HighCVSS 7.5No exploitEPSS 2%

    tryton · trytondNov 21, 2019

  • Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor.

    HighCVSS 7.1No exploitEPSS 0%

    tryton · trytondNov 29, 2025

  • An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.

    MediumCVSS 6.5No exploitEPSS 1%

    tryton · proteusMar 10, 2022

  • In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6,

    MediumCVSS 6.5No exploitEPSS 1%

    tryton · trytondApr 4, 2019

  • Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export.

    MediumCVSS 6.5No exploitEPSS 0%

    tryton · trytondNov 29, 2025

  • CVE-2012-0215
    23Monitor

    model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Ma

    MediumCVSS 5.5No exploitEPSS 2%

    tryton · trytondJul 12, 2012

  • The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under certain circumstances in

    MediumCVSS 5.9No exploitEPSS 1%

    tryton · trytonNov 22, 2018

  • CVE-2016-1241
    21Monitor

    Tryton 3.x before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allow remote authenticated user

    MediumCVSS 5.3No exploitEPSS 2%

    tryton · trytonSep 7, 2016

  • CVE-2017-0360
    21Monitor

    file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "same

    MediumCVSS 5.3No exploitEPSS 2%

    tryton · trytonApr 4, 2017

  • CVE-2016-1242
    18Monitor

    file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authenti

    MediumCVSS 4.4No exploitEPSS 2%

    tryton · trytonSep 7, 2016

  • CVE-2015-0861
    17Monitor

    model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authentic

    MediumCVSS 4.3No exploitEPSS 1%

    tryton · trytondApr 13, 2016

  • Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information.

    MediumCVSS 4.3No exploitEPSS 0%

    tryton · trytondNov 29, 2025