odoo CVE Vulnerabilities & Metrics

Focus on odoo vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About odoo Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with odoo. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total odoo CVEs: 53
Earliest CVE date: 04 Jun 2017, 21:29 UTC
Latest CVE date: 25 Feb 2025, 19:15 UTC

Latest CVE reference: CVE-2024-36259

Rolling Stats

30-day Count (Rolling): 1
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -93.75%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -93.75%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical odoo CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.57

Max CVSS: 9.0

Critical CVEs (≥9): 2

CVSS Range vs. Count

Range Count
0.0-3.9 19
4.0-6.9 28
7.0-8.9 4
9.0-10.0 2

CVSS Distribution Chart

Top 5 Highest CVSS odoo CVEs

These are the five CVEs with the highest CVSS scores for odoo, sorted by severity first and recency.

All CVEs for odoo

CVE-2024-36259 odoo vulnerability CVSS: 0 25 Feb 2025, 19:15 UTC

Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based (yes/no response) crafted attack.

CVE-2023-48050 odoo vulnerability CVSS: 0 15 Dec 2023, 01:15 UTC

SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-attendance) v. 13.0 through 16.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the db parameter in the controllers/controllers.py component.

CVE-2021-45111 odoo vulnerability CVSS: 0 25 Apr 2023, 19:15 UTC

Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger the creation of demonstration data, including user accounts with known credentials.

CVE-2021-45071 odoo vulnerability CVSS: 0 25 Apr 2023, 19:15 UTC

Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via crafted uploaded file names.

CVE-2021-44775 odoo vulnerability CVSS: 0 25 Apr 2023, 19:15 UTC

Cross-site scripting (XSS) issue in Website app of Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, by posting crafted contents.

CVE-2021-44547 odoo vulnerability CVSS: 0 25 Apr 2023, 19:15 UTC

A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading to privilege escalation.

CVE-2021-44476 odoo vulnerability CVSS: 0 25 Apr 2023, 19:15 UTC

A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read local files on the server, including sensitive configuration files.

CVE-2021-44465 odoo vulnerability CVSS: 0 25 Apr 2023, 19:15 UTC

Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated attackers to subscribe to receive future notifications and comments related to arbitrary business records in the system, via crafted RPC requests.

CVE-2021-44461 odoo vulnerability CVSS: 0 25 Apr 2023, 19:15 UTC

Cross-site scripting (XSS) issue in Accounting app of Odoo Enterprise 13.0 through 15.0, allows remote attackers who are able to control the contents of accounting journal entries to inject arbitrary web script in the browser of a victim.

CVE-2021-44460 odoo vulnerability CVSS: 0 25 Apr 2023, 19:15 UTC

Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to access the system with the deactivated account and any permission it still holds, via crafted RPC requests.

CVE-2021-26947 odoo vulnerability CVSS: 0 25 Apr 2023, 19:15 UTC

Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via a crafted link.

CVE-2021-26263 odoo vulnerability CVSS: 0 25 Apr 2023, 19:15 UTC

Cross-site scripting (XSS) issue in Discuss app of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to inject arbitrary web script in the browser of a victim, by posting crafted contents.

CVE-2021-23203 odoo vulnerability CVSS: 0 25 Apr 2023, 19:15 UTC

Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to download PDF reports for arbitrary documents, via crafted requests.

CVE-2021-23186 odoo vulnerability CVSS: 0 25 Apr 2023, 19:15 UTC

A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access and modify database contents of other tenants, in a multi-tenant system.

CVE-2021-23178 odoo vulnerability CVSS: 0 25 Apr 2023, 19:15 UTC

Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead.

CVE-2021-23176 odoo vulnerability CVSS: 0 25 Apr 2023, 19:15 UTC

Improper access control in reporting engine of l10n_fr_fec module in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to extract accounting information via crafted RPC packets.

CVE-2021-23166 odoo vulnerability CVSS: 0 25 Apr 2023, 19:15 UTC

A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and write local files on the server.

CVE-2020-29396 odoo vulnerability CVSS: 6.5 22 Dec 2020, 17:15 UTC

A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote authenticated users to execute arbitrary code, leading to privilege escalation.

CVE-2019-11786 odoo vulnerability CVSS: 4.0 22 Dec 2020, 17:15 UTC

Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to modify translated terms, which may lead to arbitrary content modification on translatable elements.

CVE-2019-11785 odoo vulnerability CVSS: 4.0 22 Dec 2020, 17:15 UTC

Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to obtain access to messages posted on business records there were not given access to, and subscribe to receive future messages.

CVE-2019-11784 odoo vulnerability CVSS: 4.0 22 Dec 2020, 17:15 UTC

Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to obtain access to arbitrary messages in conversations they were not a party to.

CVE-2019-11783 odoo vulnerability CVSS: 4.0 22 Dec 2020, 17:15 UTC

Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to subscribe to arbitrary mail channels uninvited.

CVE-2019-11782 odoo vulnerability CVSS: 4.0 22 Dec 2020, 17:15 UTC

Improper access control in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users with access to contact management to modify user accounts, leading to privilege escalation.

CVE-2019-11781 odoo vulnerability CVSS: 6.8 22 Dec 2020, 17:15 UTC

Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to trick victims into modifying their account via crafted links, leading to privilege escalation.

CVE-2018-15645 odoo vulnerability CVSS: 4.0 22 Dec 2020, 17:15 UTC

Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users to create arbitrary records via crafted payloads, which may allow privilege escalation.

CVE-2018-15641 odoo vulnerability CVSS: 3.5 22 Dec 2020, 17:15 UTC

Cross-site scripting (XSS) issue in web module in Odoo Community 11.0 through 14.0 and Odoo Enterprise 11.0 through 14.0, allows remote authenticated internal users to inject arbitrary web script in the browser of a victim via crafted calendar event attributes.

CVE-2018-15638 odoo vulnerability CVSS: 3.5 22 Dec 2020, 17:15 UTC

Cross-site scripting (XSS) issue in mail module in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted channel names.

CVE-2018-15634 odoo vulnerability CVSS: 4.3 22 Dec 2020, 17:15 UTC

Cross-site scripting (XSS) issue in attachment management in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via a crafted link.

CVE-2018-15633 odoo vulnerability CVSS: 4.3 22 Dec 2020, 17:15 UTC

Cross-site scripting (XSS) issue in "document" module in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted attachment filenames.

CVE-2018-15632 odoo vulnerability CVSS: 8.5 22 Dec 2020, 17:15 UTC

Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to initialize an empty database on which they can connect with default credentials.

CVE-2019-11780 odoo vulnerability CVSS: 5.5 19 Dec 2019, 16:16 UTC

Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authenticated attackers to access sensitive information via crafted RPC requests, which could lead to privilege escalation.

CVE-2018-14733 odoo vulnerability CVSS: 5.0 05 Jul 2019, 20:15 UTC

The Odoo Community Association (OCA) dbfilter_from_header module makes Odoo 8.x, 9.x, 10.x, and 11.x vulnerable to ReDoS (regular expression denial of service) under certain circumstances.

CVE-2018-14860 odoo vulnerability CVSS: 9.0 03 Jul 2019, 20:15 UTC

Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated privileged users to escape from the dynamic expression sandbox and execute arbitrary code on the hosting system.

CVE-2018-14859 odoo vulnerability CVSS: 5.5 03 Jul 2019, 20:15 UTC

Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated users to reset the password of other users by being the first party to use the secure token.

CVE-2018-14865 odoo vulnerability CVSS: 4.0 03 Jul 2019, 19:15 UTC

Report engine in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier does not use secure options when passing documents to wkhtmltopdf, which allows remote attackers to read local files.

CVE-2018-14864 odoo vulnerability CVSS: 4.0 03 Jul 2019, 19:15 UTC

Incorrect access control in asset bundles in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier allows remote authenticated users to inject arbitrary web script via a crafted attachment.

CVE-2018-14863 odoo vulnerability CVSS: 5.5 03 Jul 2019, 19:15 UTC

Incorrect access control in the RPC framework in Odoo Community 8.0 through 11.0 and Odoo Enterprise 9.0 through 11.0 allows authenticated users to call private functions via RPC.

CVE-2018-14862 odoo vulnerability CVSS: 5.5 03 Jul 2019, 19:15 UTC

Incorrect access control in the mail templating system in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated internal users to delete arbitrary menuitems via a crafted RPC request.

CVE-2018-14861 odoo vulnerability CVSS: 4.0 03 Jul 2019, 19:15 UTC

Improper data access control in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows authenticated users to perform a CSV export of the secure hashed passwords of other users.

CVE-2018-14866 odoo vulnerability CVSS: 4.0 03 Jul 2019, 18:15 UTC

Incorrect access control in the TransientModel framework in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated attackers to access data in transient records that they do not own by making an RPC call before garbage collection occurs.

CVE-2018-14887 odoo vulnerability CVSS: 5.8 28 Jun 2019, 18:15 UTC

Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows a remote attacker to deny access to the service and to disclose database names via a crafted request.

CVE-2018-14886 odoo vulnerability CVSS: 4.0 28 Jun 2019, 18:15 UTC

The module-description renderer in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier does not disable RST's local file inclusion, which allows privileged authenticated users to read local files via a crafted module description.

CVE-2018-14885 odoo vulnerability CVSS: 7.5 28 Jun 2019, 18:15 UTC

Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker to restore a database dump without knowing the super-admin password. An arbitrary password succeeds.

CVE-2018-14868 odoo vulnerability CVSS: 4.0 28 Jun 2019, 18:15 UTC

Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to change the password of other users without knowing their current password via a crafted RPC call.

CVE-2018-14867 odoo vulnerability CVSS: 5.0 28 Jun 2019, 18:15 UTC

Incorrect access control in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 allows remote attackers to post messages on behalf of customers, and to guess document attribute values, via crafted parameters.

CVE-2017-5871 odoo vulnerability CVSS: 5.8 22 May 2019, 20:29 UTC

Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).

CVE-2018-15640 odoo vulnerability CVSS: 9.0 09 Apr 2019, 16:29 UTC

Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated privileges via a crafted request.

CVE-2018-15635 odoo vulnerability CVSS: 4.3 09 Apr 2019, 16:29 UTC

Cross-site scripting vulnerability in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote attackers to inject arbitrary web script in the browser of an internal user of the system by tricking them into inviting a follower on a document with a crafted name.

CVE-2018-15631 odoo vulnerability CVSS: 4.0 09 Apr 2019, 16:29 UTC

Improper access control in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote authenticated attackers to e-mail themselves arbitrary files from the database, via a crafted RPC request.

CVE-2017-10805 odoo vulnerability CVSS: 6.5 04 Jul 2017, 18:29 UTC

In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, incorrect access control on OAuth tokens in the OAuth module allows remote authenticated users to hijack OAuth sessions of other users.

CVE-2017-10804 odoo vulnerability CVSS: 7.5 04 Jul 2017, 18:29 UTC

In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used.

CVE-2017-10803 odoo vulnerability CVSS: 8.5 04 Jul 2017, 18:29 UTC

In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database Anonymization module allows remote authenticated privileged users to execute arbitrary Python code, because unpickle is used.

CVE-2017-9416 odoo vulnerability CVSS: 4.0 04 Jun 2017, 21:29 UTC

Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local files readable by the Odoo service.