Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jorani HIGH 7.6
CVE-2025-67102

A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to execute arbitrary SQL commands vi…

Fix: after 1.0.4
Fix from $1,950 2026-02-17
Leave Management System MEDIUM 5.3
CVE-2023-48205

Jorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emails.

No fix yet
Fix from $1,600 2023-12-07
Leave Management System MEDIUM 6.5
CVE-2023-45540

An issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted script to the comment field of…

No fix yet
Fix from $1,600 2023-10-16
Jorani HIGH 8.8
CVE-2023-2681

An SQL Injection vulnerability has been found on Jorani version 1.0.0. This vulnerability allows an authenticated remote user, with low privileges, t…

Mitigation only
Fix from $1,950 2023-10-03
Jorani CRITICAL 9.8
CVE-2023-26469EPSS 83%

In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.

No fix yet
Fix from $2,300 2023-08-17
Jorani MEDIUM 6.1
CVE-2022-48118

Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Acronym parameter.

No fix yet
Fix from $1,600 2023-01-27
Jorani CRITICAL 9.8
CVE-2022-34132

Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leaves.php.

Patch available
Fix from $2,300 2022-06-28
Jorani HIGH 8.8
CVE-2022-34134

Jorani v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /application/controllers/Users.php.

Patch available
Fix from $1,950 2022-06-28
Jorani MEDIUM 6.1
CVE-2022-34133

Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Comment parameter at application/controllers/Leaves.php.

Patch available
Fix from $1,600 2022-06-28