Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Odoo

First CVE: Jun 4, 2017Active for: 9 yearsTotal CVEs: 54
32.8
VTI Score
Medium

Odoo operates a modestly scoped but prominent enterprise resource planning and business-management platform that underpins a range of back-office and operational workflows; despite a narrow product base, the vendor's disclosures carry broad relevance given the integration-heavy nature of ERP deployments and the sensitivity of financial and operational data they handle. Vulnerabilities affecting Odoo skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency to acquire public exploit code, making timely patching operationally important for organizations relying on the platform. The exposure recurs through access-control and input-handling weakness classes—improper access control, privilege assignment errors, and cross-site scripting flaws—that are characteristic of web-based enterprise applications where authentication boundaries and input validation are foundational to data isolation. Defenders should treat Odoo advisories as high-priority for inventory and patching workflows, particularly where instances are internet-facing or handle sensitive transactional data; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
54
Total CVEs
More Total CVEs than 99% of tracked vendors
5.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Odoo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 4, 2017
9 years ago
Most Recent CVE
Feb 25, 2025
514 days ago

Self-Reporting Analysis

Of all the CVEs published by Odoo as a CNA, 100.0% affect products that Odoo develops as a vendor.

100.0%
Self-reported: 34 (100.0%)
Third-party: 0 (0.0%)

Of all the CVEs published that affect products developed by Odoo, 63.0% are self-published by Odoo as a CNA.

63.0%
37.0%
Self-published: 34 (63.0%)
Other CNAs: 20 (37.0%)

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (54 CVEs).

54 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-9416MEDIUM
Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local files readable by the Odoo service.
Jun 4, 20176.534NOYES
CVE-2021-26947MEDIUM
Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a vi
Apr 25, 20236.133NOYES
CVE-2017-10803MEDIUM
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database Anonymization module allows remo
Jul 4, 20176.533NOYES
CVE-2018-15640HIGH
Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated privileges via a crafted request.
Apr 9, 20198.831NONO
CVE-2017-10804CRITICAL
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameter
Jul 4, 20179.831NONO
CVE-2018-14885CRITICAL
Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker to restore a database dump wit
Jun 28, 20199.830NONO
CVE-2018-14860CRITICAL
Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated privileged users to escape from the d
Jul 3, 20199.129NONO
CVE-2021-44547CRITICAL
A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading to privilege escalation.
Apr 25, 20239.128NONO
CVE-2020-29396HIGH
A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote authenticated users to execute ar
Dec 22, 20208.828NONO
CVE-2021-23186HIGH
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access and modify database contents of other tenan
Apr 25, 20238.727NONO
View all 54 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products54 CVEs
63%
26%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (1.9%)
Network53 (98.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low53 (98.1%)
High1 (1.9%)
Unknown0 (0.0%)
User Interaction
None41 (75.9%)
Unknown0 (0.0%)
Required13 (24.1%)
Privileges Required
Low28 (51.9%)
High7 (13.0%)
None19 (35.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (54 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
5.6% of CVEs· 96th percentile
ExploitDB
1 CVE
1.9% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Odoo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Odoo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Odoo's Products

View all 2 CNAs →

Top CWEs