Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Tryton

First CVE: Jul 12, 2012Active for: 14 yearsTotal CVEs: 16
18.1
VTI Score
Low

Tryton is a modestly represented, open-source enterprise resource planning platform whose vulnerability footprint centers on its server component (Trytond), client interface (Tryton), and protocol library (Proteus). The recurring exposure involves access-control and information-disclosure weaknesses—including incorrect authorization, sensitive-data exposure, path traversal, command injection, and improper privilege management—that reflect the authentication and input-handling demands of a multi-tenant business application. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Tryton over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 12, 2012
14 years ago
Most Recent CVE
Jan 30, 2026
175 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-6633HIGH
The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7, and 3.2.x before 3.2.3 allows remote authenticated users to
Apr 12, 20188.827NONO
CVE-2022-26662HIGH
An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton App
Mar 10, 20227.526NONO
CVE-2025-66423HIGH
Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
Nov 30, 20257.125NONO
CVE-2012-2238HIGH
trytond 2.4: ModelView.button fails to validate authorization
Nov 21, 20197.524NONO
CVE-2020-37014MEDIUM
Tryton 5.4 contains a persistent cross-site scripting vulnerability in the user profile name input that allows remote attackers to inject malicious scripts. Attackers can exploit t
Jan 30, 20266.423NONO
CVE-2022-26661MEDIUM
An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Comm
Mar 10, 20226.523NONO
CVE-2019-10868MEDIUM
In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated user can order records
Apr 5, 20196.523NONO
CVE-2025-66424MEDIUM
Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
Nov 30, 20256.522NONO
CVE-2018-19443MEDIUM
The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under certain circumstances in bus.py and jsonrpc.py. This connection
Nov 22, 20185.920NONO
CVE-2013-4510HIGH
Directory traversal vulnerability in the client in Tryton 3.0.0, as distributed before 20131104 and earlier, allows remote servers to write arbitrary files via path separators in t
Nov 18, 20137.820NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
69%
31%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network14 (87.5%)
Unknown2 (12.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (62.5%)
High4 (25.0%)
Unknown2 (12.5%)
User Interaction
None14 (87.5%)
Unknown2 (12.5%)
Required0 (0.0%)
Privileges Required
Low10 (62.5%)
High1 (6.3%)
None3 (18.8%)
Unknown2 (12.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Tryton.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Tryton — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Tryton's Products

View all 4 CNAs →

Top CWEs