Logicaldoc
19 known vulnerabilities
Top Products
LogicalDOC Enterprise 7.7.4 contains multiple post-authentication file disclosure vulnerabilities that allow attackers t
A vulnerability was identified in LogicalDOC Community Edition up to 9.2.1. This vulnerability affects unknown code of t
A vulnerability was determined in LogicalDOC Community Edition up to 9.2.1. This affects an unknown part of the componen
A security flaw has been discovered in LogicalDOC Community Edition up to 9.2.1. This issue affects some unknown process
The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticat
The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying
There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthentica
LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site script
LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site script
LogicalDOC Enterprise is vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the i
LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site script
A local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation. Depend
LogicalDoc before 8.3.3 allows /servlet.gupld Directory Traversal, a different vulnerability than CVE-2020-9423 and CVE-
LogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of
LogicalDoc before 8.3.3 allows SQL Injection. LogicalDoc populates the list of available documents by querying the datab
LogicalDOC Community Edition 8.x before 8.2.1 has a path traversal vulnerability that allows reading arbitrary files and
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to an XSS when using preview on HTML document.
LogicalDoc Community Edition 7.5.3 and prior contain an Incorrect access control which could leave to privilege escalati
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.
Frequently Asked Questions
How many CVEs affect Logicaldoc?
Logicaldoc has 19 CVE records in our database, including 1 critical and 8 high severity vulnerabilities.
What are the most severe Logicaldoc vulnerabilities?
Logicaldoc has 1 critical severity (CVSS 9.0+) and 8 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Logicaldoc vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Logicaldoc products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Logicaldoc Vulnerabilities
CyberStrike scans your infrastructure for Logicaldoc vulnerabilities and provides real-time remediation guidance.
Get Started