Known Vulnerabilities for products from Sql-ledger
Listed below are 16 of the newest known vulnerabilities associated with the vendor "Sql-ledger".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-61069 json | Not Provided | 2026-07-21 | 2026-07-21 | |
| CVE-2026-60795 json | Not Provided | 2026-07-21 | 2026-07-21 | |
| CVE-2026-60678 json | Not Provided | 2026-07-21 | 2026-07-21 | |
| CVE-2026-60494 json | Not Provided | 2026-07-21 | 2026-07-21 | |
| CVE-2026-56077 json | Not Provided | 2026-06-18 | 2026-06-23 | |
| CVE-2026-46937 json | Not Provided | 2026-06-17 | 2026-06-18 | |
| CVE-2026-46893 json | Not Provided | 2026-06-17 | 2026-06-18 | |
| CVE-2026-41586 json | Not Provided | 2026-05-07 | 2026-05-07 | |
| CVE-2025-15645 json | Not Provided | 2026-05-19 | 2026-05-20 | |
| CVE-2023-7346 json | Not Provided | 2026-05-20 | 2026-05-20 | |
| CVE-2009-4402 json | The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations by pr... | Not Provided | 2009-12-23 | 2026-04-23 |
| CVE-2009-3584 json | SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote a... | Not Provided | 2009-12-23 | 2026-04-23 |
| CVE-2009-3583 json | Directory traversal vulnerability in the Preferences menu item in SQL-Ledger 2.8.24 allows remote attackers to include and ex... | Not Provided | 2009-12-23 | 2026-04-23 |
| CVE-2009-3582 json | Multiple SQL injection vulnerabilities in the delete subroutine in SQL-Ledger 2.8.24 allow remote authenticated users to exec... | Not Provided | 2009-12-23 | 2026-04-23 |
| CVE-2009-3581 json | Multiple cross-site scripting (XSS) vulnerabilities in SQL-Ledger 2.8.24 allow remote authenticated users to inject arbitrary... | Not Provided | 2009-12-23 | 2026-04-23 |
| CVE-2009-3580 json | Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger 2.8.24 allows remote attackers to hijack the authentic... | Not Provided | 2009-12-23 | 2026-04-23 |
| CVE-2008-4078 json | SQL injection vulnerability in the AR/AP transaction report in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 a... | Not Provided | 2008-09-15 | 2026-04-23 |
| CVE-2008-4077 json | The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a... | Not Provided | 2008-09-15 | 2026-04-23 |
| CVE-2007-1923 json | (1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, wh... | Not Provided | 2007-04-10 | 2026-04-23 |
| CVE-2007-1541 json | Directory traversal vulnerability in am.pl in SQL-Ledger 2.6.27 only checks for the presence of a NULL (%00) character to pro... | Not Provided | 2007-03-20 | 2026-04-23 |