Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Espocrm CRITICAL 9.1
CVE-2026-33656

EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing …

Fix: 9.3.4+
Fix from $2,300 2026-04-22
Espocrm HIGH 7.2
CVE-2026-33733

EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template management endpoints accept attack…

Fix: 9.3.4+
Fix from $1,950 2026-04-22
Espocrm MEDIUM 5.4
CVE-2026-33740

EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Email/importEml endpoint contai…

Fix: 9.3.4+
Fix from $1,600 2026-04-13
Espocrm MEDIUM 5.4
CVE-2026-33657

EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML injection vulnerability that allo…

Fix: 9.3.4+
Fix from $1,600 2026-04-13
Espocrm HIGH 8.1
CVE-2020-37094

EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to bypass two-factor authentica…

Fix: after 5.8.5
Fix from $1,950 2026-02-03
Espocrm MEDIUM 5.4
CVE-2025-59428

EspoCRM is an open source customer relationship management application. In versions before 9.1.9, a vulnerability allows arbitrary user creation, inc…

Fix: 9.1.9+
Fix from $1,600 2025-10-14
Espocrm MEDIUM 6.5
CVE-2025-52892

EspoCRM is a web application with a frontend designed as a single-page application and a REST API backend written in PHP. In versions 9.1.6 and below…

Fix: 9.1.7+
Fix from $1,600 2025-08-05
Espocrm MEDIUM 6.5
CVE-2025-52575

EspoCRM is an Open Source CRM (Customer Relationship Management) software. EspoCRM versions 9.1.6 and earlier are vulnerable to blind LDAP Injection …

Fix: 9.1.7+
Fix from $1,600 2025-07-21
Espocrm HIGH 8.5
CVE-2025-32390

EspoCRM is a free, open-source customer relationship management platform. Prior to version 9.0.8, HTML Injection in Knowledge Base (KB) articles lead…

Fix: 9.0.8+
Fix from $1,950 2025-05-12
Espocrm MEDIUM 6.5
CVE-2025-32385

EspoCRM is an Open Source Customer Relationship Management software. Prior to 9.0.5, Iframe dashlet allows user to display iframes with arbitrary URL…

Fix: 9.0.5+
Fix from $1,600 2025-04-16
Espocrm MEDIUM 5.9
CVE-2024-24818

EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "Password Change" page and redi…

Fix: 8.1.2+
Fix from $1,600 2024-03-21
Espocrm MEDIUM 6.5
CVE-2023-46736

EspoCRM is an Open Source CRM (Customer Relationship Management) software. In affected versions there is Server-Side Request Forgery (SSRF) vulnerabi…

Fix: after 8.0.2
Fix from $1,600 2023-12-05
Espocrm HIGH 7.2
CVE-2023-5966

An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, …

Fix: after 7.5.2
Fix from $1,950 2023-11-30
Espocrm HIGH 7.2
CVE-2023-5965

An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the update form, which could le…

Fix: after 7.5.2
Fix from $1,950 2023-11-30
Espocrm HIGH 8.8
CVE-2022-38843

EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server. Attacke…

No fix yet
Fix from $1,950 2022-09-16
Espocrm HIGH 8.0
CVE-2022-38844

CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloads capabl…

No fix yet
Fix from $1,950 2022-09-16
Espocrm MEDIUM 6.1
CVE-2022-38845

Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending crafted csv f…

No fix yet
Fix from $1,600 2022-09-16
Espocrm MEDIUM 5.9
CVE-2022-38846

EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attack…

No fix yet
Fix from $1,600 2022-09-16
Espocrm MEDIUM 5.4
CVE-2021-3539

EspoCRM 6.1.6 and prior suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This …

Fix: after 6.1.6
Fix from $1,600 2021-08-04
Espocrm MEDIUM 5.4
CVE-2019-14546

An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending an email when a malicious pa…

Fix: 5.6.9+
Fix from $1,600 2019-08-05
Espocrm MEDIUM 5.4
CVE-2019-14547

An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin with malicious JavaScript in th…

Fix: 5.6.9+
Fix from $1,600 2019-08-05
Espocrm MEDIUM 5.4
CVE-2019-14548

An issue was discovered in EspoCRM before 5.6.9. Stored XSS in the body of an Article was executed when a victim opens articles received through mail…

Fix: 5.6.9+
Fix from $1,600 2019-08-05
Espocrm MEDIUM 5.4
CVE-2019-14549

An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed inside the title and breadcrumb of a newly formed entity available to all th…

Fix: 5.6.9+
Fix from $1,600 2019-08-05
Espocrm MEDIUM 5.4
CVE-2019-14550

An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a victim clicks on the Edit Dashboard feature present on the Homepage. …

Fix: 5.6.9+
Fix from $1,600 2019-08-05
Espocrm HIGH 8.8
CVE-2019-14351

EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user password hash by 1 symbol at…

No fix yet
Fix from $1,950 2019-07-28
Espocrm MEDIUM 6.1
CVE-2019-14349

EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for storing do…

No fix yet
Fix from $1,600 2019-07-28
Espocrm MEDIUM 6.1
CVE-2019-14350

EspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base. A malicious attacker can inject Java…

No fix yet
Fix from $1,600 2019-07-28
Espocrm MEDIUM 6.1
CVE-2019-14329

An issue was discovered in EspoCRM before 5.6.6. There is stored XSS due to lack of filtration of user-supplied data in Create Task. A malicious atta…

Fix: 5.6.6+
Fix from $1,600 2019-07-28
Espocrm MEDIUM 6.1
CVE-2019-14330

An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create Case. A malicious attack…

Fix: 5.6.6+
Fix from $1,600 2019-07-28
Espocrm MEDIUM 6.1
CVE-2019-14331

An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create User. A malicious attack…

Fix: 5.6.6+
Fix from $1,600 2019-07-28