← Back

Inoideas

inoideas

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Inoerp
inoerp

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Inoideas
1Inoerp
Mar 2, 2026
Feb 11, 2026
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
InoERP 0.7.2 contains a persistent cross-site scripting vulnerability in the comment section that allows unauthenticated attackers to inject malicious scripts. Attackers can submit comments with JavaScript payloads that...Show more
InoERP 0.7.2 contains a persistent cross-site scripting vulnerability in the comment section that allows unauthenticated attackers to inject malicious scripts. Attackers can submit comments with JavaScript payloads that execute in other users' browsers, potentially stealing cookies and session information.Show less
1Inoideas
1Inoerp
Nov 21, 2024
Feb 10, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In InoERP 0.7.2, an unauthorized attacker can execute arbitrary code on the server side due to lack of validations in /modules/sys/form_personalization/json_fp.php.
1Inoideas
1Inoerp
Nov 21, 2024
Sep 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
download.php in inoERP 4.15 allows SQL injection through insecure deserialization.