Jorani
by Jorani
Source repositories
CVEs (10)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-26469 | Cri | 0.73 | 9.8 | 0.82 | Aug 17, 2023 | In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server. | ||
| CVE-2023-2681 | Hig | 0.57 | 8.8 | 0.01 | Oct 3, 2023 | An SQL Injection vulnerability has been found on Jorani version 1.0.0. This vulnerability allows an authenticated remote user, with low privileges, to send queries with malicious SQL code on the "/leaves/validate" path and the “id” parameter, managing to extract arbritary… | ||
| CVE-2025-67102 | Hig | 0.49 | 7.6 | 0.00 | Feb 17, 2026 | A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to execute arbitrary SQL commands via the entity parameter. | ||
| CVE-2022-48118 | Med | 0.40 | 6.1 | 0.00 | Jan 27, 2023 | Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Acronym parameter. | ||
| CVE-2018-15917 | Med | 0.39 | 5.4 | 0.06 | Sep 5, 2018 | Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session/language. | ||
| CVE-2018-15918 | Med | 0.38 | 5.4 | 0.03 | Sep 5, 2018 | An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive information from the database used by the application via the startdate or enddate parameter to leaves/validate. | ||
| CVE-2023-53870 | Med | 0.33 | — | 0.00 | Dec 15, 2025 | Jorani 1.0.3 contains a reflected cross-site scripting vulnerability in the language parameter that allows attackers to inject malicious scripts. Attackers can craft XSS payloads in the language parameter to execute arbitrary JavaScript and potentially steal user session… | ||
| CVE-2022-34134 | Hig | 0.00 | 8.8 | 0.00 | Jun 28, 2022 | Jorani v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /application/controllers/Users.php. | ||
| CVE-2022-34133 | Med | 0.00 | 6.1 | 0.01 | Jun 28, 2022 | Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Comment parameter at application/controllers/Leaves.php. | ||
| CVE-2022-34132 | Cri | 0.00 | 9.8 | 0.01 | Jun 28, 2022 | Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leaves.php. |
- risk 0.73cvss 9.8epss 0.82
In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.
- risk 0.57cvss 8.8epss 0.01
An SQL Injection vulnerability has been found on Jorani version 1.0.0. This vulnerability allows an authenticated remote user, with low privileges, to send queries with malicious SQL code on the "/leaves/validate" path and the “id” parameter, managing to extract arbritary…
- risk 0.49cvss 7.6epss 0.00
A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to execute arbitrary SQL commands via the entity parameter.
- risk 0.40cvss 6.1epss 0.00
Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Acronym parameter.
- risk 0.39cvss 5.4epss 0.06
Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session/language.
- risk 0.38cvss 5.4epss 0.03
An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive information from the database used by the application via the startdate or enddate parameter to leaves/validate.
- risk 0.33cvss —epss 0.00
Jorani 1.0.3 contains a reflected cross-site scripting vulnerability in the language parameter that allows attackers to inject malicious scripts. Attackers can craft XSS payloads in the language parameter to execute arbitrary JavaScript and potentially steal user session…
- risk 0.00cvss 8.8epss 0.00
Jorani v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /application/controllers/Users.php.
- risk 0.00cvss 6.1epss 0.01
Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Comment parameter at application/controllers/Leaves.php.
- risk 0.00cvss 9.8epss 0.01
Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leaves.php.