Weberp is a small enterprise resource planning and accounting application with a narrow product footprint that nonetheless sits among the more prominent in its category. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the application's exposure to untrusted input and the severity impact of flaws in financial and business-logic systems; the recurring weakness classes—SQL injection, insecure file accessibility, unsafe inclusion of untrusted functionality, and improper permission assignment—are characteristic of legacy web applications with evolving security awareness. Defenders should treat this vendor's advisories as high-priority and verify patch deployment across deployed instances; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Weberp over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13292CRITICAL A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it is deserialized. Then, this deserialized data goe | Jul 4, 2019 | 9.8 | 46 | NO | YES |
CVE-2015-10018CRITICAL A vulnerability has been found in DBRisinajumi d2files and classified as critical. Affected by this vulnerability is the function actionUpload/actionDownloadFile of the file contro | Jan 6, 2023 | 9.8 | 30 | NO | NO |
CVE-2025-46052CRITICAL An error-based SQL Injection (SQLi) vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL command and extract sensitive data by injecting a crafted payload into | May 15, 2025 | 9.8 | 27 | NO | NO |
CVE-2020-37082HIGH webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database backup files without authentication. Attackers can directly ac | Feb 3, 2026 | 7.5 | 25 | NO | NO |
CVE-2019-7755HIGH In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the execution of arbitrary SQL queries, aka | Mar 30, 2020 | 8.8 | 24 | NO | NO |
CVE-2018-19436HIGH An issue was discovered in the Manufacturing component in webERP 4.15. CollectiveWorkOrderCost.php has Blind SQL Injection via the SearchParts parameter. | Nov 22, 2018 | 7.2 | 23 | NO | NO |
CVE-2018-19435HIGH An issue was discovered in the Sales component in webERP 4.15. SalesInquiry.php has SQL Injection via the SortBy parameter. | Nov 22, 2018 | 7.2 | 23 | NO | NO |
CVE-2018-19434HIGH An issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15. BankMatching.php has Blind SQL injection via the AmtClear_ | Nov 22, 2018 | 7.2 | 23 | NO | NO |
CVE-2018-20420MEDIUM In webERP 4.15, Z_CreateCompanyTemplateFile.php has Incorrect Access Control, leading to the overwrite of an existing .sql file on the target web site by creating a template and th | Dec 24, 2018 | 4.9 | 18 | NO | NO |
CVE-2025-46053MEDIUM A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive data by injecting a crafted payload into the ReportID and R | May 15, 2025 | 5.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Weberp.
Media articles that mention a CVE ID that affects a product developed by Weberp — matched by CVE ID, not by vendor name.