Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Logicaldoc

19 known vulnerabilities

1
CRITICAL
8
HIGH
7
MEDIUM
3
LOW

Top Products

logicaldoc 19
19 CVEs
7.5
CVE-2019-25258

LogicalDOC Enterprise 7.7.4 contains multiple post-authentication file disclosure vulnerabilities that allow attackers t

3.7
CVE-2025-12547

A vulnerability was identified in LogicalDOC Community Edition up to 9.2.1. This vulnerability affects unknown code of t

3.5
CVE-2025-12546

A vulnerability was determined in LogicalDOC Community Edition up to 9.2.1. This affects an unknown part of the componen

3.5
CVE-2025-11946

A security flaw has been discovered in LogicalDOC Community Edition up to 9.2.1. This issue affects some unknown process

8.8
CVE-2024-54449

The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticat

7.2
CVE-2024-54448

The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying

6.1
CVE-2024-12020

There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthentica

5.4
CVE-2022-47418

LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site script

5.4
CVE-2022-47417

LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site script

5.4
CVE-2022-47416

LogicalDOC Enterprise is vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the i

5.4
CVE-2022-47415

LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site script

7.8
CVE-2020-13542

A local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation. Depend

7.5
CVE-2020-10366

LogicalDoc before 8.3.3 allows /servlet.gupld Directory Traversal, a different vulnerability than CVE-2020-9423 and CVE-

9.8
CVE-2020-9423

LogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of

6.5
CVE-2020-10365

LogicalDoc before 8.3.3 allows SQL Injection. LogicalDoc populates the list of available documents by querying the datab

7.1
CVE-2019-9723

LogicalDOC Community Edition 8.x before 8.2.1 has a path traversal vulnerability that allows reading arbitrary files and

5.4
CVE-2017-1000023

LogicalDoc Community Edition 7.5.3 and prior is vulnerable to an XSS when using preview on HTML document.

8.8
CVE-2017-1000022

LogicalDoc Community Edition 7.5.3 and prior contain an Incorrect access control which could leave to privilege escalati

8.8
CVE-2017-1000021

LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.

Frequently Asked Questions

How many CVEs affect Logicaldoc?

Logicaldoc has 19 CVE records in our database, including 1 critical and 8 high severity vulnerabilities.

What are the most severe Logicaldoc vulnerabilities?

Logicaldoc has 1 critical severity (CVSS 9.0+) and 8 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Logicaldoc vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Logicaldoc products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Logicaldoc Vulnerabilities

CyberStrike scans your infrastructure for Logicaldoc vulnerabilities and provides real-time remediation guidance.

Get Started