Openbravo develops an enterprise resource planning platform whose vulnerability footprint centers on its core ERP application, with the recurring signal in application-layer access and data-handling issues: path traversal flaws enabling unauthorized file access and SQL injection weaknesses in query construction. Treat this as a focused vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openbravo over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction | Nov 2, 2013 | 3.5 | 36 | NO | YES |
CVE-2017-9437HIGH Openbravo Business Suite 3.0 is affected by SQL injection. This vulnerability could allow remote authenticated attackers to inject arbitrary SQL code. | Jun 5, 2017 | 8.8 | 27 | NO | NO |
CVE-2019-14362MEDIUM Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Traversal. This vulnerability could allow remote authenticated attackers to replace a file on the server via the getAttach | Jul 28, 2019 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openbravo.
Media articles that mention a CVE ID that affects a product developed by Openbravo — matched by CVE ID, not by vendor name.