CVE-2022-26662High· 7.5▾ TwilightXML Entity Expansion in trytond and proteus
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.9%
1.9% → 2.0%
An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An unauthenticated user can send a crafted XML-RPC message to consume all the resources of the server.
trytond >= 5.0.0, < 5.0.46trytond >= 6.0.0, < 6.0.16trytond >= 6.1.0, < 6.2.6proteus >= 5.0.0, < 5.0.12proteus >= 6.0.0, < 6.0.5proteus >= 6.1.0, < 6.2.2Upgrade to a patched release:
trytond 5.0.46trytond 6.0.16trytond 6.2.6proteus 5.0.12proteus 6.0.5proteus 6.2.2Connected by shared product, vendor, weakness, or advisory.
CVE-2022-26661Medium· 6.5Improper Restriction of XML External Entity Reference in trytond and proteus
CVE-2013-4510High· 7.5Tryton Directory Traversal vulnerability
CVE-2025-66423High· 7.1trytond does not enforce access rights for the route of the HTML editor.
CVE-2025-66422Medium· 4.3trytond allows remote attackers to obtain sensitive trace-back (server setup) information
CVE-2025-66424Medium· 6.5trytond does not enforce access rights for data export