Letodms is a document management system with a narrow, focused product portfolio centered on file organization and access control. Its vulnerability pattern reflects common web-application weaknesses affecting the administrative and sharing functions: cross-site request forgery and path-traversal issues that undermine document isolation and administrative intent. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Letodms over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-2006MEDIUM Directory traversal vulnerability in op/op.Login.php in LetoDMS (formerly MyDMS) 1.7.2 and earlier allows remote authenticated users to include and execute arbitrary local files vi | May 20, 2010 | 6.5 | 35 | NO | YES |
CVE-2012-4570CRITICAL SQL injection vulnerability in LetoDMS_Core/Core/inc.ClassDMS.php in LetoDMS (formerly MyDMS) before 3.3.8 allows remote attackers to execute arbitrary SQL commands via unspecified | Oct 23, 2017 | 9.8 | 31 | NO | NO |
CVE-2012-4568HIGH Multiple cross-site request forgery (CSRF) vulnerabilities in LetoDMS (formerly MyDMS) before 3.3.8 allow remote attackers to hijack the authentication of unspecified victims via u | Oct 23, 2017 | 8.8 | 25 | NO | NO |
CVE-2010-2007MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in LetoDMS (formerly MyDMS) 1.7.2 and earlier allow remote attackers to hijack the authentication of administrators for r | May 20, 2010 | 6.8 | 23 | NO | NO |
CVE-2012-4569MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in out/out.UsrMgr.php in LetoDMS (formerly MyDMS) before 3.3.9 allow remote attackers to inject arbitrary web script or HTML via | Oct 23, 2017 | 6.1 | 20 | NO | NO |
CVE-2012-4567MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in LetoDMS (formerly MyDMS) before 3.3.8 allow remote attackers to inject arbitrary web script or HTML via unspecified parameter | Oct 23, 2017 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Letodms.
Media articles that mention a CVE ID that affects a product developed by Letodms — matched by CVE ID, not by vendor name.