Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
12013.1%CRITICAL

Related CVEs

2
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2019-25312InoERP 0.7.2 contains a persistent cross-site scripting vulnerability in the comment section that allows unauthenticated attackers to inject malicious scripts. Attackers can submit comments with JavaScript payloads that execute in other users' browsers, potentially stealing cookies and session information.MEDIUM5.113.1%Feb 11, 2026
CVE-2020-28870In InoERP 0.7.2, an unauthorized attacker can execute arbitrary code on the server side due to lack of validations in /modules/sys/form_personalization/json_fp.php.CRITICAL9.8Feb 10, 2021