Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Crmeb MEDIUM 5.3
CVE-2026-1734

A security flaw has been discovered in Zhong Bang CRMEB up to 5.6.3. This vulnerability affects unknown code of the file crmeb/app/api/controller/v1/…

Fix: after 5.6.3
Fix from $1,600 2026-02-02
Crmeb CRITICAL 9.8
CVE-2026-1202

A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file crmeb/app/api/controller/v1/Log…

Fix: after 5.6.3
Fix from $2,300 2026-01-20
Crmeb HIGH 8.1
CVE-2026-1203

A weakness has been identified in CRMEB up to 5.6.3. The impacted element is the function remoteRegister of the file crmeb/app/services/user/LoginSer…

Fix: after 5.6.3
Fix from $1,950 2026-01-20
Crmeb HIGH 7.2
CVE-2025-15443

A vulnerability was identified in CRMEB up to 5.6.1. This issue affects some unknown processing of the file /adminapi/product/product_export. Such ma…

Fix: after 5.6.1
Fix from $1,950 2026-01-04
Crmeb HIGH 7.2
CVE-2025-15442

A vulnerability was determined in CRMEB up to 5.6.1. This vulnerability affects unknown code of the file /adminapi/export/product_list. This manipula…

Fix: after 5.6.1
Fix from $1,950 2026-01-04
Crmeb HIGH 8.1
CVE-2025-11290

A vulnerability was identified in CRMEB up to 5.6.1. This affects an unknown function of the component JWT HMAC Secret Handler. Such manipulation of …

Fix: after 5.6.1
Fix from $1,950 2025-10-05
Crmeb HIGH 8.8
CVE-2025-11288

A security flaw has been discovered in CRMEB up to 5.6. This issue affects some unknown processing of the file /adminapi/product/product of the compo…

Fix: after 5.6
Fix from $1,950 2025-10-05
Crmeb HIGH 8.8
CVE-2025-10391

A security vulnerability has been detected in CRMEB up to 5.6.1. The impacted element is the function testOutUrl of the file app/services/out/OutAcco…

Fix: after 5.6.1
Fix from $1,950 2025-09-14
Crmeb HIGH 8.8
CVE-2025-10390

A weakness has been identified in CRMEB up to 5.6.1. The affected element is the function editAddress of the file app/services/user/UserAddressServic…

Fix: after 5.6.1
Fix from $1,950 2025-09-14
Crmeb HIGH 8.8
CVE-2025-10389

A security flaw has been discovered in CRMEB up to 5.6.1. Impacted is the function Save of the file app/services/system/admin/SystemAdminServices.php…

Fix: after 5.6.1
Fix from $1,950 2025-09-14
Crmeb CRITICAL 9.8
CVE-2025-25763

crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php

Mitigation only
Fix from $2,300 2025-03-06
Crmeb HIGH 7.5
CVE-2024-52726

CRMEB v5.4.0 is vulnerable to Arbitrary file read in the save_basics function which allows an attacker to obtain sensitive information

Mitigation only
Fix from $1,950 2024-11-22
Crmeb HIGH 7.5
CVE-2024-50653

CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able to claim coupons once by captu…

Fix: after 5.4.0
Fix from $1,950 2024-11-15
Crmeb HIGH 7.5
CVE-2024-6944

A vulnerability was found in ZhongBangKeJi CRMEB up to 5.4.0 and classified as critical. Affected by this issue is the function get_image_base64 of t…

Fix: after 5.4.0
Fix from $1,950 2024-07-21
Crmeb HIGH 8.8
CVE-2024-6943

A vulnerability has been found in ZhongBangKeJi CRMEB up to 5.4.0 and classified as critical. Affected by this vulnerability is the function download…

Fix: after 5.4.0
Fix from $1,950 2024-07-21
Crmeb HIGH 7.5
CVE-2024-36837EPSS 8%

SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductC…

Mitigation only
Fix from $1,950 2024-06-05
Crmeb Java MEDIUM 5.3
CVE-2024-33117

crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeContr…

Mitigation only
Fix from $1,600 2024-05-06
Crmeb Java HIGH 8.1
CVE-2024-28714

SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter.

Fix: 1.3.4+
Fix from $1,950 2024-03-28
Crmeb Java MEDIUM 6.5
CVE-2024-24110

SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET request to the component /api/…

Fix: 1.3.4+
Fix from $1,600 2024-03-21
Crmeb Java HIGH 7.5
CVE-2024-25469

SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitude and long…

No fix yet
Fix from $1,950 2024-02-23
Crmeb HIGH 8.1
CVE-2024-1704

A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been declared as critical. This vulnerability affects the function save/delete of the …

No fix yet
Fix from $1,950 2024-02-21
Crmeb MEDIUM 5.3
CVE-2024-1703

A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been classified as problematic. This affects the function openfile of the file /admina…

No fix yet
Fix from $1,600 2024-02-21
Crmeb CRITICAL 9.8
CVE-2023-3234

A vulnerability was found in Zhong Bang CRMEB up to 4.6.0. It has been declared as problematic. Affected by this vulnerability is the function put_im…

Fix: after 4.6.0
Fix from $2,300 2023-06-14
Crmeb HIGH 8.8
CVE-2023-3233

A vulnerability was found in Zhong Bang CRMEB up to 4.6.0. It has been classified as critical. Affected is the function get_image_base64 of the file …

Fix: after 4.6.0
Fix from $1,950 2023-06-14
Crmeb CRITICAL 9.8
CVE-2023-3232

A vulnerability was found in Zhong Bang CRMEB up to 4.6.0 and classified as critical. This issue affects some unknown processing of the file /api/wec…

Fix: after 4.6.0
Fix from $2,300 2023-06-14
Crmeb CRITICAL 9.8
CVE-2023-30185

CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.

Fix: after 4.6.0
Fix from $2,300 2023-05-08
Crmeb HIGH 7.2
CVE-2023-2419

A vulnerability was found in Zhong Bang CRMEB 4.6.0. It has been declared as critical. This vulnerability affects the function videoUpload of the fil…

No fix yet
Fix from $1,950 2023-04-29
Crmeb Java CRITICAL 9.8
CVE-2023-1608

A vulnerability was found in Zhong Bang CRMEB Java up to 1.3.4. It has been declared as critical. This vulnerability affects the function getAdminLis…

Fix: after 1.3.4
Fix from $2,300 2023-03-23
Crmeb Java MEDIUM 5.4
CVE-2023-1609

A vulnerability was found in Zhong Bang CRMEB Java up to 1.3.4. It has been rated as problematic. This issue affects the function save of the file /a…

Fix: after 1.3.4
Fix from $1,600 2023-03-23
Crmeb Java HIGH 7.2
CVE-2023-25223

CRMEB <=1.3.4 is vulnerable to SQL Injection via /api/admin/user/list.

Fix: after 1.3.4
Fix from $1,950 2023-03-07