CVE-2022-26661Medium· 6.5▾ SunlitImproper Restriction of XML External Entity Reference in trytond and proteus
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.4%
1.4% → 1.4%
An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An authenticated user can make the server parse a crafted XML SEPA file to access arbitrary files on the system.
trytond >= 5.0.0, < 5.0.46trytond >= 6.0.0, < 6.0.16trytond >= 6.1.0, < 6.2.6proteus >= 5.0.0, < 5.0.12proteus >= 6.0.0, < 6.0.5proteus >= 6.1.0, < 6.2.2Upgrade to a patched release:
trytond 5.0.46trytond 6.0.16trytond 6.2.6proteus 5.0.12proteus 6.0.5proteus 6.2.2Connected by shared product, vendor, weakness, or advisory.
CVE-2022-26662High· 7.5XML Entity Expansion in trytond and proteus
CVE-2013-4510High· 7.5Tryton Directory Traversal vulnerability
CVE-2025-66423High· 7.1trytond does not enforce access rights for the route of the HTML editor.
CVE-2025-66422Medium· 4.3trytond allows remote attackers to obtain sensitive trace-back (server setup) information
CVE-2025-66424Medium· 6.5trytond does not enforce access rights for data export