Vulnerability index

Browse CVEs

9 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Espocrm HIGH 8.8
CVE-2022-38843

EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server. Attacke…

No fix yet
Fix from $1,950 2022-09-16
Espocrm HIGH 8.0
CVE-2022-38844

CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloads capabl…

No fix yet
Fix from $1,950 2022-09-16
Espocrm MEDIUM 6.1
CVE-2022-38845

Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending crafted csv f…

No fix yet
Fix from $1,600 2022-09-16
Espocrm MEDIUM 5.9
CVE-2022-38846

EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attack…

No fix yet
Fix from $1,600 2022-09-16
Espocrm HIGH 8.8
CVE-2019-14351

EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user password hash by 1 symbol at…

No fix yet
Fix from $1,950 2019-07-28
Espocrm MEDIUM 6.1
CVE-2019-14349

EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for storing do…

No fix yet
Fix from $1,600 2019-07-28
Espocrm MEDIUM 6.1
CVE-2019-14350

EspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base. A malicious attacker can inject Java…

No fix yet
Fix from $1,600 2019-07-28
Espocrm MEDIUM 5.4
CVE-2018-17301

Reflected XSS exists in client/res/templates/global-search/name-field.tpl in EspoCRM 5.3.6 via /#Account in the search panel.

No fix yet
Fix from $1,600 2018-09-21
Espocrm MEDIUM 5.4
CVE-2018-17302

Stored XSS exists in views/fields/wysiwyg.js in EspoCRM 5.3.6 via a /#Email/view saved draft message.

No fix yet
Fix from $1,600 2018-09-21