Inoideas
Inoideas Inoerp: vulnerabilities and CVEs
Inoideas Inoerp has 3 published vulnerabilities, 1 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs3
Last 12 months1
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-25312 | Medium (5.1) | 0.24% | — | Feb 11, 2026 | InoERP 0.7.2 contains a persistent cross-site scripting vulnerability in the comment section that allows unauthenticated attackers to inject malicious scripts. Attackers can submit comments with JavaScript payloads that… |
| CVE-2020-28870 | Critical (9.8) | 3.1% | — | Feb 10, 2021 | In InoERP 0.7.2, an unauthorized attacker can execute arbitrary code on the server side due to lack of validations in /modules/sys/form_personalization/json_fp.php. |
| CVE-2019-16894 | Critical (9.8) | 3.0% | — | Sep 26, 2019 | download.php in inoERP 4.15 allows SQL injection through insecure deserialization. |