← Back

Openbravo Erp

openbravo_erp

Vendor: Openbravo • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openbravo
1Openbravo Erp
Jun 17, 2026
Jul 28, 2019
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Traversal. This vulnerability could allow remote authenticated attackers to replace a file on the server via the getAttachmentDirectoryForNewAttachment inpKey val...Show more
Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Traversal. This vulnerability could allow remote authenticated attackers to replace a file on the server via the getAttachmentDirectoryForNewAttachment inpKey value.Show less
1Openbravo
1Openbravo Erp
May 13, 2026
Jun 5, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Openbravo Business Suite 3.0 is affected by SQL injection. This vulnerability could allow remote authenticated attackers to inject arbitrary SQL code.
1Openbravo
1Openbravo Erp
Apr 29, 2026
Nov 2, 2013
N/A· v4
N/A· v3
3.5 LOW· v2
The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUs...Show more
The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue.Show less