Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ledgersmb

First CVE: Sep 13, 2006Active for: 20 yearsTotal CVEs: 18
54.6
VTI Score
TOP TARGET

LedgerSMB is a small-footprint open-source accounting and enterprise resource planning application that has attracted a concentrated vulnerability footprint despite its niche deployment. The vendor's exposure skews toward serious outcomes, with an elevated tendency toward critical-severity findings and frequent public exploit availability; the recurring weakness classes—including cross-site scripting, SQL injection, cross-site request forgery, and improper output encoding—are characteristic of web application input and output handling. Defenders should treat updates to this accounting platform as high-priority given both the severity profile and the sensitivity of financial data it protects; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ledgersmb over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 13, 2006
19 years ago
Most Recent CVE
Feb 2, 2024
902 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-3694CRITICAL
LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code
Aug 23, 20219.630NONO
CVE-2021-3693CRITICAL
LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote
Aug 23, 20219.630NONO
CVE-2018-9246CRITICAL
The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variable values used as part of shell command ex
Jun 8, 20189.828NONO
CVE-2007-1329HIGH
Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files, and execute arbitrary code, via . (dot)
Mar 7, 200710.026NONO
CVE-2007-5372HIGH
Multiple SQL injection vulnerabilities in (a) LedgerSMB 1.0.0 through 1.2.7 and (b) DWS Systems SQL-Ledger 2.x allow remote attackers to execute arbitrary SQL commands via (1) the
Oct 11, 200710.025NONO
CVE-2007-3907HIGH
Unspecified vulnerability in login.pl in LedgerSMB 1.2.0 through 1.2.6 allows remote attackers to bypass authentication and perform certain actions as an arbitrary user via unspeci
Jul 19, 200710.025NONO
CVE-2008-4077HIGH
The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a denial of service (resource exhaustion) via an HTTP PO
Sep 15, 20087.824NONO
CVE-2006-4731MEDIUM
Multiple directory traversal vulnerabilities in (1) login.pl and (2) admin.pl in (a) SQL-Ledger before 2.6.19 and (b) LedgerSMB before 1.0.0p1 allow remote attackers to execute arb
Sep 13, 20065.024NOYES
CVE-2024-23831HIGH
LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an active session in /setup.pl, an attacker can trick the admin into click
Feb 2, 20247.523NONO
CVE-2021-3882MEDIUM
LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reverse proxy. By tricking a user
Oct 14, 20216.823NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
33%
50%
17%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (33.3%)
Unknown12 (66.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (22.2%)
High2 (11.1%)
Unknown12 (66.7%)
User Interaction
None1 (5.6%)
Unknown12 (66.7%)
Required5 (27.8%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (33.3%)
Unknown12 (66.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
11.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ledgersmb.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ledgersmb — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ledgersmb's Products

View all 3 CNAs →

Top CWEs