Toptech Systems TMS7

10 known vulnerabilities in Toptech Systems TMS7, 2 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-72510 CVSS 8.5 high The "supplier_no" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection.
  • CVE-2026-72507 CVSS 8.5 high The "reportType" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind…
  • CVE-2026-71379 CVSS 10.0 critical The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.
  • CVE-2026-71302 CVSS 7.5 high The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an…
  • CVE-2026-71189 CVSS 4.8 medium An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to…
  • CVE-2026-70356 CVSS 9.4 critical The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP…
  • CVE-2026-69662 CVSS 2.1 low The application uses unsafe functions that allow execution of inline scripts and string evaluation functions.
  • CVE-2026-68954 CVSS 8.5 high The "pattern" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection…
  • CVE-2026-68068 CVSS 8.5 high The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a…
  • CVE-2026-63713 CVSS 8.5 high The "search" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection…