trytond vulnerabilities
CVEs whose affected-version data names the trytond package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
7 CVEsRSS
CVE-2025-66423High· 7.1trytond does not enforce access rights for the route of the HTML editor.
trytond does not enforce access rights for the route of the HTML editor.
▾ Twilighttrytond · trytondEPSS 0.23%via OSV
CVE-2025-66422Medium· 4.3trytond allows remote attackers to obtain sensitive trace-back (server setup) information
trytond allows remote attackers to obtain sensitive trace-back (server setup) information
▾ Sunlittrytond · trytondEPSS 0.29%via OSV
CVE-2025-66424Medium· 6.5trytond does not enforce access rights for data export
trytond does not enforce access rights for data export
▾ Sunlittrytond · trytondEPSS 0.24%via OSV
CVE-2013-4510High· 7.5Tryton Directory Traversal vulnerability
Tryton Directory Traversal vulnerability
▾ Twilighttrytond · trytondEPSS 2.2%via OSV
CVE-2014-6633High· 8.8Tryton vulnerable to arbitrary command execution
Tryton vulnerable to arbitrary command execution
▾ Twilighttryton · trytonEPSS 2.1%via OSV
CVE-2022-26662High· 7.5XML Entity Expansion in trytond and proteus
XML Entity Expansion in trytond and proteus
▾ Twilighttrytond · trytondEPSS 2.0%via OSV
CVE-2022-26661Medium· 6.5Improper Restriction of XML External Entity Reference in trytond and proteus
Improper Restriction of XML External Entity Reference in trytond and proteus
▾ Sunlittrytond · trytondEPSS 1.4%via OSV