VYPR

Aureuserp

by Aureuserp

Source repositories

CVEs (5)

  • CVE-2026-95655HigSep 22, 2026
    risk 0.46cvss 8.1epss 0.00

    Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access arbitrary messages. Attackers can submit sequential message IDs to read, edit, delete, or pin messages from other departments or companies, and…

  • CVE-2026-97062MedSep 24, 2026
    risk 0.28cvss 5.4epss 0.00

    Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG files containing JavaScript. Attackers can craft SVG files with script elements that execute in the…

  • CVE-2026-94387MedSep 21, 2026
    risk 0.28cvss 5.4epss 0.00

    Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping. Any user permitted to edit tracked text fields can inject malicious markup that executes when…

  • CVE-2026-93454MedSep 18, 2026
    risk 0.28cvss 5.4epss 0.00

    Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoint, which persists to the database and…

  • CVE-2026-4175LowMar 16, 2026
    risk 0.16cvss 3.5epss 0.00

    A vulnerability was determined in Aureus ERP up to 1.3.0-BETA2. The affected element is an unknown function of the file plugins/webkul/chatter/resources/views/filament/infolists/components/messages/content-text-entry.blade.php of the component Chatter Message Handler. Executing…