Vulnerability index

Browse CVEs

48 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Odoo MEDIUM 6.5
CVE-2024-36259

Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive inf…

No fix yet
Fix from $1,600 2025-02-25
Odoo HIGH 8.8
CVE-2024-12368

Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens o…

No fix yet
Fix from $1,950 2025-02-25
Odoo HIGH 8.1
CVE-2021-45111

Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger the crea…

Fix: after 15.0
Fix from $1,950 2023-04-25
Odoo CRITICAL 9.1
CVE-2021-44547

A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading to privile…

Fix: after 15.0
Fix from $2,300 2023-04-25
Odoo HIGH 8.7
CVE-2021-23166

A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and write loca…

Fix: after 15.0
Fix from $1,950 2023-04-25
Odoo HIGH 8.7
CVE-2021-23186

A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access and modify d…

Fix: after 15.0
Fix from $1,950 2023-04-25
Odoo HIGH 7.5
CVE-2021-23178

Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a t…

Fix: after 15.0
Fix from $1,950 2023-04-25
Odoo HIGH 7.5
CVE-2021-23203

Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to do…

Patch available
Fix from $1,950 2023-04-25
Odoo MEDIUM 6.8
CVE-2021-44476

A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read local files on…

Fix: after 15.0
Fix from $1,600 2023-04-25
Odoo MEDIUM 6.5
CVE-2021-23176

Improper access control in reporting engine of l10n_fr_fec module in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remo…

Fix: after 15.0
Fix from $1,600 2023-04-25
Odoo MEDIUM 6.5
CVE-2021-44460

Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to access the …

Fix: after 13.0
Fix from $1,600 2023-04-25
Odoo MEDIUM 6.1
CVE-2021-26263

Cross-site scripting (XSS) issue in Discuss app of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers t…

Patch available
Fix from $1,600 2023-04-25
Odoo MEDIUM 6.1
CVE-2021-26947

Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary we…

Fix: after 15.0
Fix from $1,600 2023-04-25
Odoo MEDIUM 6.1
CVE-2021-44461

Cross-site scripting (XSS) issue in Accounting app of Odoo Enterprise 13.0 through 15.0, allows remote attackers who are able to control the contents…

Fix: after 15.0
Fix from $1,600 2023-04-25
Odoo MEDIUM 6.1
CVE-2021-44775

Cross-site scripting (XSS) issue in Website app of Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to i…

Fix: after 15.0
Fix from $1,600 2023-04-25
Odoo MEDIUM 6.1
CVE-2021-45071

Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary we…

Fix: after 15.0
Fix from $1,600 2023-04-25
Odoo HIGH 8.8
CVE-2019-11781

Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to tri…

Fix: after 12.0
Fix from $1,950 2020-12-22
Odoo HIGH 8.8
CVE-2020-29396

A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote au…

Fix: after 13.0
Fix from $1,950 2020-12-22
Odoo MEDIUM 6.5
CVE-2018-15645

Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users …

Fix: after 12.0
Fix from $1,600 2020-12-22
Odoo MEDIUM 6.5
CVE-2019-11782

Improper access control in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users with access to con…

Fix: after 14.0
Fix from $1,600 2020-12-22
Odoo MEDIUM 6.5
CVE-2019-11783

Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote auth…

Fix: after 14.0
Fix from $1,600 2020-12-22
Odoo MEDIUM 6.5
CVE-2019-11784

Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authent…

Fix: after 14.0
Fix from $1,600 2020-12-22
Odoo CRITICAL 9.1
CVE-2018-15632

Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers…

Fix: after 11.0
Fix from $2,300 2020-12-22
Odoo MEDIUM 6.1
CVE-2018-15633

Cross-site scripting (XSS) issue in "document" module in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attacker…

Fix: after 11.0
Fix from $1,600 2020-12-22
Odoo MEDIUM 6.1
CVE-2018-15634

Cross-site scripting (XSS) issue in attachment management in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote atta…

Fix: after 14.0
Fix from $1,600 2020-12-22
Odoo MEDIUM 5.4
CVE-2018-15638

Cross-site scripting (XSS) issue in mail module in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote attackers to i…

Fix: after 13.0
Fix from $1,600 2020-12-22
Odoo MEDIUM 5.4
CVE-2018-15641

Cross-site scripting (XSS) issue in web module in Odoo Community 11.0 through 14.0 and Odoo Enterprise 11.0 through 14.0, allows remote authenticated…

Fix: after 14.0
Fix from $1,600 2020-12-22
Odoo HIGH 8.1
CVE-2019-11780

Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authenticated at…

Patch available
Fix from $1,950 2019-12-19
Odoo HIGH 7.5
CVE-2018-14733

The Odoo Community Association (OCA) dbfilter_from_header module makes Odoo 8.x, 9.x, 10.x, and 11.x vulnerable to ReDoS (regular expression denial o…

Mitigation only
Fix from $1,950 2019-07-05
Odoo CRITICAL 9.1
CVE-2018-14860

Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated privil…

Fix: after 11.0
Fix from $2,300 2019-07-03