VYPR
Vendor

Weberp

Products
3
CVEs
10
Across products
12
Status
Private

Products

3

Recent CVEs

10
  • CVE-2019-13292CriJul 4, 2019
    risk 0.67cvss 9.8epss 0.07

    A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it is deserialized. Then, this deserialized data goes directly into a SQL query, with no sanitizing checks.

  • CVE-2025-46052CriMay 15, 2025
    risk 0.64cvss 9.8epss 0.00

    An error-based SQL Injection (SQLi) vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL command and extract sensitive data by injecting a crafted payload into the DEL form field in a POST request to /StockCounts.php

  • CVE-2019-7755HigMar 30, 2020
    risk 0.57cvss 8.8epss 0.02

    In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the execution of arbitrary SQL queries, aka SQL Injection.

  • CVE-2018-19436HigNov 22, 2018
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in the Manufacturing component in webERP 4.15. CollectiveWorkOrderCost.php has Blind SQL Injection via the SearchParts parameter.

  • CVE-2018-19435HigNov 22, 2018
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in the Sales component in webERP 4.15. SalesInquiry.php has SQL Injection via the SortBy parameter.

  • CVE-2018-19434HigNov 22, 2018
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15. BankMatching.php has Blind SQL injection via the AmtClear_ parameter.

  • CVE-2020-22474MedFeb 22, 2021
    risk 0.42cvss 6.5epss 0.01

    In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local file inclusion.

  • CVE-2025-46053MedMay 15, 2025
    risk 0.33cvss 5.1epss 0.00

    A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive data by injecting a crafted payload into the ReportID and ReplaceReportID parameters within a POST request to /reportwriter/admin/ReportCreator.php

  • CVE-2018-20420MedDec 24, 2018
    risk 0.32cvss 4.9epss 0.01

    In webERP 4.15, Z_CreateCompanyTemplateFile.php has Incorrect Access Control, leading to the overwrite of an existing .sql file on the target web site by creating a template and then using ../ directory traversal in the TemplateName parameter.

  • CVE-2020-37082Feb 3, 2026
    risk 0.00cvss epss 0.01

    webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database backup files without authentication. Attackers can directly access generated backup files in the companies/weberp/ directory by requesting the…