Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3392
  • PyPI/trytond
XML Entity Expansion in trytond and proteus 09 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-3391
  • PyPI/trytond
Improper Restriction of XML External Entity Reference in trytond and proteus 09 Jul
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-1989
  • PyPI/trytond
trytond does not enforce access rights for data export 07 Jul
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-1990
  • PyPI/trytond
trytond allows remote attackers to obtain sensitive trace-back (server setup) information 07 Jul
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-1991
  • PyPI/trytond
trytond does not enforce access rights for the route of the HTML editor. 07 Jul
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-1054
  • PyPI/trytond
Tryton Directory Traversal vulnerability 06 Jul
  • No fix available
  • Severity - 8.7 (High)
GHSA-2w93-qwpp-vgvj
  • PyPI/trytond
trytond does not enforce access rights for data export 30 Nov 2025
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-jqfc-9q34-prhg
  • PyPI/trytond
trytond allows remote attackers to obtain sensitive trace-back (server setup) information 30 Nov 2025
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-p3p5-xrmv-4j6x
  • PyPI/trytond
trytond does not enforce access rights for the route of the HTML editor. 30 Nov 2025
  • Fix available
  • Severity - 7.1 (High)
GHSA-qjmc-wwmw-cq9r
  • PyPI/trytond
Tryton Directory Traversal vulnerability 17 May 2022
  • No fix available
  • Severity - 8.7 (High)
GHSA-52j9-v3jc-9xgc
  • PyPI/trytond
Tryton allows users to read the hashed password 17 May 2022
  • Fix available
  • Severity - 6.0 (Medium)
GHSA-jpr7-8rxm-4vgx
  • PyPI/trytond
Tryton allow authenticated users with certain permissions to read arbitrary files via the name parameter 17 May 2022
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-m9jj-5qvj-5fhx
  • PyPI/tryton
  • PyPI/trytond
Tryton vulnerable to arbitrary command execution 14 May 2022
  • Fix available
  • Severity - 8.7 (High)
GHSA-c8q5-2j73-qvcc
  • PyPI/trytond
trytond arbitrary fields write via a sequence of records 14 May 2022
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-7cwg-2575-3546
  • PyPI/trytond
Tryton Information Disclosure Vulnerability 13 May 2022
  • Fix available
  • Severity - 6.0 (Medium)
GHSA-cqg4-rf29-3mv6
  • PyPI/trytond
Trytond allows modification of privileges of arbitrary users 04 May 2022
  • Fix available
  • Severity - 7.1 (High)