Webkul Aureus ERP

4 known vulnerabilities in Webkul Aureus ERP, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-97062 CVSS 5.1 medium Aureus ERP through 1.6.0, fixed in commit 53ad76d, stores uploaded SVG files on its public disk and serves them from the application…
  • CVE-2026-95655 CVSS 8.6 high Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access…
  • CVE-2026-94387 CVSS 5.1 medium Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value…
  • CVE-2026-93454 CVSS 5.1 medium Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated…