Known Vulnerabilities for products from Sql-ledger
Listed below are 16 of the newest known vulnerabilities associated with the vendor "Sql-ledger".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-72909 json | Not Provided | 2026-08-10 | 2026-08-11 | |
| CVE-2026-70803 json | Not Provided | 2026-08-18 | 2026-08-19 | |
| CVE-2026-70796 json | Not Provided | 2026-08-18 | 2026-08-18 | |
| CVE-2026-70764 json | Not Provided | 2026-08-18 | 2026-08-19 | |
| CVE-2026-70713 json | Not Provided | 2026-08-18 | 2026-08-18 | |
| CVE-2026-70686 json | Not Provided | 2026-08-18 | 2026-08-18 | |
| CVE-2026-68823 json | Not Provided | 2026-08-07 | 2026-08-07 | |
| CVE-2026-61069 json | Not Provided | 2026-07-21 | 2026-07-24 | |
| CVE-2026-60795 json | Not Provided | 2026-07-21 | 2026-07-24 | |
| CVE-2026-60769 json | Not Provided | 2026-08-18 | 2026-08-21 | |
| CVE-2009-4402 json | The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations by pr... | Not Provided | 2009-12-23 | 2026-04-23 |
| CVE-2009-3584 json | SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote a... | Not Provided | 2009-12-23 | 2026-04-23 |
| CVE-2009-3583 json | Directory traversal vulnerability in the Preferences menu item in SQL-Ledger 2.8.24 allows remote attackers to include and ex... | Not Provided | 2009-12-23 | 2026-04-23 |
| CVE-2009-3582 json | Multiple SQL injection vulnerabilities in the delete subroutine in SQL-Ledger 2.8.24 allow remote authenticated users to exec... | Not Provided | 2009-12-23 | 2026-04-23 |
| CVE-2009-3581 json | Multiple cross-site scripting (XSS) vulnerabilities in SQL-Ledger 2.8.24 allow remote authenticated users to inject arbitrary... | Not Provided | 2009-12-23 | 2026-04-23 |
| CVE-2009-3580 json | Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger 2.8.24 allows remote attackers to hijack the authentic... | Not Provided | 2009-12-23 | 2026-04-23 |
| CVE-2008-4078 json | SQL injection vulnerability in the AR/AP transaction report in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 a... | Not Provided | 2008-09-15 | 2026-04-23 |
| CVE-2008-4077 json | The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a... | Not Provided | 2008-09-15 | 2026-04-23 |
| CVE-2007-1923 json | (1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, wh... | Not Provided | 2007-04-10 | 2026-04-23 |
| CVE-2007-1541 json | Directory traversal vulnerability in am.pl in SQL-Ledger 2.6.27 only checks for the presence of a NULL (%00) character to pro... | Not Provided | 2007-03-20 | 2026-04-23 |