Vulnerability index

Browse CVEs

9 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2022-38843 EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server. Attacke… Espocrm No fix yet Fix from $1,9502022-09-16 HIGH 8.0 CVE-2022-38844 CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloads capabl… Espocrm No fix yet Fix from $1,9502022-09-16 MEDIUM 6.1 CVE-2022-38845 Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending crafted csv f… Espocrm No fix yet Fix from $1,6002022-09-16 MEDIUM 5.9 CVE-2022-38846 EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attack… Espocrm No fix yet Fix from $1,6002022-09-16 HIGH 8.8 CVE-2019-14351 EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user password hash by 1 symbol at… Espocrm No fix yet Fix from $1,9502019-07-28 MEDIUM 6.1 CVE-2019-14349 EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for storing do… Espocrm No fix yet Fix from $1,6002019-07-28 MEDIUM 6.1 CVE-2019-14350 EspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base. A malicious attacker can inject Java… Espocrm No fix yet Fix from $1,6002019-07-28 MEDIUM 5.4 CVE-2018-17301 Reflected XSS exists in client/res/templates/global-search/name-field.tpl in EspoCRM 5.3.6 via /#Account in the search panel. Espocrm No fix yet Fix from $1,6002018-09-21 MEDIUM 5.4 CVE-2018-17302 Stored XSS exists in views/fields/wysiwyg.js in EspoCRM 5.3.6 via a /#Email/view saved draft message. Espocrm No fix yet Fix from $1,6002018-09-21