Tryton is a modestly represented, open-source enterprise resource planning platform whose vulnerability footprint centers on its server component (Trytond), client interface (Tryton), and protocol library (Proteus). The recurring exposure involves access-control and information-disclosure weaknesses—including incorrect authorization, sensitive-data exposure, path traversal, command injection, and improper privilege management—that reflect the authentication and input-handling demands of a multi-tenant business application. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tryton over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-6633HIGH The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7, and 3.2.x before 3.2.3 allows remote authenticated users to | Apr 12, 2018 | 8.8 | 27 | NO | NO |
CVE-2022-26662HIGH An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton App | Mar 10, 2022 | 7.5 | 26 | NO | NO |
CVE-2025-66423HIGH Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70. | Nov 30, 2025 | 7.1 | 25 | NO | NO |
CVE-2012-2238HIGH trytond 2.4: ModelView.button fails to validate authorization | Nov 21, 2019 | 7.5 | 24 | NO | NO |
CVE-2020-37014MEDIUM Tryton 5.4 contains a persistent cross-site scripting vulnerability in the user profile name input that allows remote attackers to inject malicious scripts. Attackers can exploit t | Jan 30, 2026 | 6.4 | 23 | NO | NO |
CVE-2022-26661MEDIUM An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Comm | Mar 10, 2022 | 6.5 | 23 | NO | NO |
CVE-2019-10868MEDIUM In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated user can order records | Apr 5, 2019 | 6.5 | 23 | NO | NO |
CVE-2025-66424MEDIUM Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70. | Nov 30, 2025 | 6.5 | 22 | NO | NO |
CVE-2018-19443MEDIUM The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under certain circumstances in bus.py and jsonrpc.py. This connection | Nov 22, 2018 | 5.9 | 20 | NO | NO |
CVE-2013-4510HIGH Directory traversal vulnerability in the client in Tryton 3.0.0, as distributed before 20131104 and earlier, allows remote servers to write arbitrary files via path separators in t | Nov 18, 2013 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tryton.
Media articles that mention a CVE ID that affects a product developed by Tryton — matched by CVE ID, not by vendor name.