Adempiere is an open-source enterprise resource planning platform with a narrow product footprint centered on its core ERP suite and associated marketplace extension (Bazaar). The observed vulnerability signal relates to general categorization rather than a specific, well-defined weakness class, reflecting the limited disclosure history around this vendor. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Adempiere over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4050HIGH Unspecified vulnerability in WebUI in ADempiere Bazaar before 3.3 beta Victoria edition allows remote attackers to access system-level windows via unspecified vectors. | Jul 30, 2007 | 10.0 | 25 | NO | NO |
CVE-2007-2760HIGH The canUpdate function in model/MRole.java in Adempiere before 3.1.6 does not properly validate user roles, which allows remote authenticated read-only users to gain read-write pri | May 18, 2007 | 9.0 | 22 | NO | NO |
CVE-2007-2759HIGH Multiple SQL injection vulnerabilities in the insert function in the ValuePreference class (grid/ed/ValuePreference.java) in Adempiere before 3.1.6 allow remote attackers to execut | May 18, 2007 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Adempiere.
Media articles that mention a CVE ID that affects a product developed by Adempiere — matched by CVE ID, not by vendor name.