Odoo operates a modestly scoped but prominent enterprise resource planning and business-management platform that underpins a range of back-office and operational workflows; despite a narrow product base, the vendor's disclosures carry broad relevance given the integration-heavy nature of ERP deployments and the sensitivity of financial and operational data they handle. Vulnerabilities affecting Odoo skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency to acquire public exploit code, making timely patching operationally important for organizations relying on the platform. The exposure recurs through access-control and input-handling weakness classes—improper access control, privilege assignment errors, and cross-site scripting flaws—that are characteristic of web-based enterprise applications where authentication boundaries and input validation are foundational to data isolation. Defenders should treat Odoo advisories as high-priority for inventory and patching workflows, particularly where instances are internet-facing or handle sensitive transactional data; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Odoo over time
Of all the CVEs published by Odoo as a CNA, 100.0% affect products that Odoo develops as a vendor.
Of all the CVEs published that affect products developed by Odoo, 63.0% are self-published by Odoo as a CNA.
Signals from CVEs in this vendor scope (54 CVEs).
54 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9416MEDIUM Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local files readable by the Odoo service. | Jun 4, 2017 | 6.5 | 34 | NO | YES |
CVE-2021-26947MEDIUM Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a vi | Apr 25, 2023 | 6.1 | 33 | NO | YES |
CVE-2017-10803MEDIUM In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database Anonymization module allows remo | Jul 4, 2017 | 6.5 | 33 | NO | YES |
CVE-2018-15640HIGH Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated privileges via a crafted request. | Apr 9, 2019 | 8.8 | 31 | NO | NO |
CVE-2017-10804CRITICAL In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameter | Jul 4, 2017 | 9.8 | 31 | NO | NO |
CVE-2018-14885CRITICAL Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker to restore a database dump wit | Jun 28, 2019 | 9.8 | 30 | NO | NO |
CVE-2018-14860CRITICAL Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated privileged users to escape from the d | Jul 3, 2019 | 9.1 | 29 | NO | NO |
CVE-2021-44547CRITICAL A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading to privilege escalation. | Apr 25, 2023 | 9.1 | 28 | NO | NO |
CVE-2020-29396HIGH A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote authenticated users to execute ar | Dec 22, 2020 | 8.8 | 28 | NO | NO |
CVE-2021-23186HIGH A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access and modify database contents of other tenan | Apr 25, 2023 | 8.7 | 27 | NO | NO |
Signals from CVEs in this vendor scope (54 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Odoo.
Media articles that mention a CVE ID that affects a product developed by Odoo — matched by CVE ID, not by vendor name.