LedgerSMB is a small-footprint open-source accounting and enterprise resource planning application that has attracted a concentrated vulnerability footprint despite its niche deployment. The vendor's exposure skews toward serious outcomes, with an elevated tendency toward critical-severity findings and frequent public exploit availability; the recurring weakness classes—including cross-site scripting, SQL injection, cross-site request forgery, and improper output encoding—are characteristic of web application input and output handling. Defenders should treat updates to this accounting platform as high-priority given both the severity profile and the sensitivity of financial data it protects; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ledgersmb over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3694CRITICAL LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code | Aug 23, 2021 | 9.6 | 30 | NO | NO |
CVE-2021-3693CRITICAL LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote | Aug 23, 2021 | 9.6 | 30 | NO | NO |
CVE-2018-9246CRITICAL The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variable values used as part of shell command ex | Jun 8, 2018 | 9.8 | 28 | NO | NO |
CVE-2007-1329HIGH Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files, and execute arbitrary code, via . (dot) | Mar 7, 2007 | 10.0 | 26 | NO | NO |
CVE-2007-5372HIGH Multiple SQL injection vulnerabilities in (a) LedgerSMB 1.0.0 through 1.2.7 and (b) DWS Systems SQL-Ledger 2.x allow remote attackers to execute arbitrary SQL commands via (1) the | Oct 11, 2007 | 10.0 | 25 | NO | NO |
CVE-2007-3907HIGH Unspecified vulnerability in login.pl in LedgerSMB 1.2.0 through 1.2.6 allows remote attackers to bypass authentication and perform certain actions as an arbitrary user via unspeci | Jul 19, 2007 | 10.0 | 25 | NO | NO |
CVE-2008-4077HIGH The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a denial of service (resource exhaustion) via an HTTP PO | Sep 15, 2008 | 7.8 | 24 | NO | NO |
CVE-2006-4731MEDIUM Multiple directory traversal vulnerabilities in (1) login.pl and (2) admin.pl in (a) SQL-Ledger before 2.6.19 and (b) LedgerSMB before 1.0.0p1 allow remote attackers to execute arb | Sep 13, 2006 | 5.0 | 24 | NO | YES |
CVE-2024-23831HIGH LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an active session in /setup.pl, an attacker can trick the admin into click | Feb 2, 2024 | 7.5 | 23 | NO | NO |
CVE-2021-3882MEDIUM LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reverse proxy. By tricking a user | Oct 14, 2021 | 6.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ledgersmb.
Media articles that mention a CVE ID that affects a product developed by Ledgersmb — matched by CVE ID, not by vendor name.