Known Vulnerabilities for Harmony by Cleo
Listed below are 2 of the newest known vulnerabilities associated with "Harmony" by "Cleo".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-84115 json | A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connec... | Not Provided | 2026-09-01 | 2026-09-01 |
| CVE-2026-84114 json | A vulnerability has been found in Cleo Harmony up to 5.8.1.10. Impacted is the function LocalUserUtil.getNativeUserByAssertio... | Not Provided | 2026-09-01 | 2026-09-01 |
| CVE-2025-56385 json | A SQL injection vulnerability exists in the login functionality of WellSky Harmony version 4.1.0.2.83 within the 'xmHarmony.a... | Not Provided | 2025-11-12 | 2026-07-05 |
| CVE-2024-55956 json | In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import an... | Not Provided | 2024-12-13 | 2026-08-05 |
| CVE-2024-50623 json | In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload ... | Not Provided | 2024-10-28 | 2026-07-31 |