Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2019-25258
LogicalDOC Enterprise 7.7.4 contains multiple post-authentication file disclosure vulnerabilities that allow attackers to read arbitrary files throug…
Logicaldoc
No fix yet
HIGH 8.1
CVE-2025-12547
A vulnerability was identified in LogicalDOC Community Edition up to 9.2.1. This vulnerability affects unknown code of the file /login.jsp of the com…
Logicaldoc
after 9.2.1
MEDIUM 5.4
CVE-2025-12546
A vulnerability was determined in LogicalDOC Community Edition up to 9.2.1. This affects an unknown part of the component API Key creation UI. This m…
Logicaldoc
after 9.2.1
MEDIUM 5.4
CVE-2025-11946
A security flaw has been discovered in LogicalDOC Community Edition up to 9.2.1. This issue affects some unknown processing of the file /frontend.jsp…
Logicaldoc
after 9.2.1
HIGH 8.8
CVE-2024-54449
The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticated attacker to write a file w…
Logicaldoc
9.1+
HIGH 7.2
CVE-2024-54448
The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying operating system. An account …
Logicaldoc
9.1+
MEDIUM 6.1
CVE-2024-12020
There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthenticated attacker could deceive a …
Logicaldoc
Mitigation only
MEDIUM 5.4
CVE-2022-47418
LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the do…
Logicaldoc
No fix yet
MEDIUM 5.4
CVE-2022-47415
LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the in…
Logicaldoc
No fix yet
MEDIUM 5.4
CVE-2022-47416
LogicalDOC Enterprise is vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the in-app chat system.
Logicaldoc
No fix yet
MEDIUM 5.4
CVE-2022-47417
LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the do…
Logicaldoc
No fix yet
HIGH 7.8
CVE-2020-13542
A local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation. Depending on the vector chosen, an …
Logicaldoc
No fix yet
HIGH 7.5
CVE-2020-10366
LogicalDoc before 8.3.3 allows /servlet.gupld Directory Traversal, a different vulnerability than CVE-2020-9423 and CVE-2020-10365.
Logicaldoc
8.3.3+
CRITICAL 9.8
CVE-2020-9423EPSS 5%
LogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of data from the database. Logic…
Logicaldoc
8.3.3+
MEDIUM 6.5
CVE-2020-10365
LogicalDoc before 8.3.3 allows SQL Injection. LogicalDoc populates the list of available documents by querying the database. This list could be filte…
Logicaldoc
8.3.3+
HIGH 7.1
CVE-2019-9723
LogicalDOC Community Edition 8.x before 8.2.1 has a path traversal vulnerability that allows reading arbitrary files and the creation of directories,…
Logicaldoc
8.2.1+
HIGH 8.8
CVE-2017-1000021
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.
Logicaldoc
after 7.5.3
HIGH 8.8
CVE-2017-1000022
LogicalDoc Community Edition 7.5.3 and prior contain an Incorrect access control which could leave to privilege escalation.
Logicaldoc
after 7.5.3
MEDIUM 5.4
CVE-2017-1000023
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to an XSS when using preview on HTML document.
Logicaldoc
after 7.5.3