VYPR
Vendor

Jorani

Products
1
CVEs
10
Across products
10
Status
Private

Products

1

Recent CVEs

10
  • CVE-2023-26469CriAug 17, 2023
    risk 0.73cvss 9.8epss 0.82

    In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.

  • CVE-2023-2681HigOct 3, 2023
    risk 0.57cvss 8.8epss 0.01

    An SQL Injection vulnerability has been found on Jorani version 1.0.0. This vulnerability allows an authenticated remote user, with low privileges, to send queries with malicious SQL code on the "/leaves/validate" path and the “id” parameter, managing to extract arbritary…

  • CVE-2025-67102HigFeb 17, 2026
    risk 0.49cvss 7.6epss 0.00

    A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to execute arbitrary SQL commands via the entity parameter.

  • CVE-2022-48118MedJan 27, 2023
    risk 0.40cvss 6.1epss 0.00

    Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Acronym parameter.

  • CVE-2018-15917MedSep 5, 2018
    risk 0.39cvss 5.4epss 0.06

    Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session/language.

  • CVE-2018-15918MedSep 5, 2018
    risk 0.38cvss 5.4epss 0.03

    An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive information from the database used by the application via the startdate or enddate parameter to leaves/validate.

  • CVE-2023-53870MedDec 15, 2025
    risk 0.33cvss epss 0.00

    Jorani 1.0.3 contains a reflected cross-site scripting vulnerability in the language parameter that allows attackers to inject malicious scripts. Attackers can craft XSS payloads in the language parameter to execute arbitrary JavaScript and potentially steal user session…

  • CVE-2022-34134HigJun 28, 2022
    risk 0.00cvss 8.8epss 0.00

    Jorani v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /application/controllers/Users.php.

  • CVE-2022-34133MedJun 28, 2022
    risk 0.00cvss 6.1epss 0.01

    Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Comment parameter at application/controllers/Leaves.php.

  • CVE-2022-34132CriJun 28, 2022
    risk 0.00cvss 9.8epss 0.01

    Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leaves.php.