VendorsAroxschool_erp_pro1.0
Vulnerabilities

Arox School ERP Pro 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2020-37090
School ERP Pro 1.0 - Remote Code Execution
Published 2026-02-03 · Analyzed
9.8EPSS 0.008
CVE-2020-37089
School ERP Pro 1.0 - 'es_messagesid' SQL Injection
Published 2026-02-03 · Analyzed
9.8EPSS 0.004
CVE-2022-32119
Arox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo function at photogalleries.inc.php and the import staff excel function at 1finance_master.inc.php.
Published 2022-07-15 · Modified
8.8EPSS 0.020
CVE-2020-37088
School ERP Pro 1.0 - Arbitrary File Read
Published 2026-02-03 · Analyzed
8.7EPSS 0.027
CVE-2020-37084
School ERP Pro 1.0 Admin Profile Photo Upload Remote Code Execution Vulnerability
Published 2026-02-03 · Analyzed
8.6EPSS 0.009
CVE-2022-32118
Arox School ERP Pro v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the dispatchcategory parameter in backoffice.inc.php.
Published 2022-07-15 · Modified
6.1EPSS 0.011