Webkul Aureus ERP
4 known vulnerabilities in Webkul Aureus ERP, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-97062 CVSS 5.1 medium Aureus ERP through 1.6.0, fixed in commit 53ad76d, stores uploaded SVG files on its public disk and serves them from the application…
- CVE-2026-95655 CVSS 8.6 high Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access…
- CVE-2026-94387 CVSS 5.1 medium Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value…
- CVE-2026-93454 CVSS 5.1 medium Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated…