Skip to main content

Vendor/product archive

tryton / trytond CVEs

Beta · best-effort

9 CVEs tagged to tryton / trytond0 Critical, 3 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2025-66424

Published Nov 30, 2025

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66423

Published Nov 30, 2025

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66422

Published Nov 30, 2025

Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10868

Published Apr 5, 2019

In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated user can order record…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0861

Published Apr 13, 2016

model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access re…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0215

Published Jul 12, 2012

model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1