Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.1
CVE-2026-33656
EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing …
Espocrm
9.3.4+
HIGH 7.2
CVE-2026-33733
EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template management endpoints accept attack…
Espocrm
9.3.4+
MEDIUM 5.4
CVE-2026-33740
EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Email/importEml endpoint contai…
Espocrm
9.3.4+
MEDIUM 5.4
CVE-2026-33657
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML injection vulnerability that allo…
Espocrm
9.3.4+
HIGH 8.1
CVE-2020-37094
EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to bypass two-factor authentica…
Espocrm
after 5.8.5
MEDIUM 5.4
CVE-2025-59428
EspoCRM is an open source customer relationship management application. In versions before 9.1.9, a vulnerability allows arbitrary user creation, inc…
Espocrm
9.1.9+
MEDIUM 6.5
CVE-2025-52892
EspoCRM is a web application with a frontend designed as a single-page application and a REST API backend written in PHP. In versions 9.1.6 and below…
Espocrm
9.1.7+
MEDIUM 6.5
CVE-2025-52575
EspoCRM is an Open Source CRM (Customer Relationship Management) software. EspoCRM versions 9.1.6 and earlier are vulnerable to blind LDAP Injection …
Espocrm
9.1.7+
HIGH 8.5
CVE-2025-32390
EspoCRM is a free, open-source customer relationship management platform. Prior to version 9.0.8, HTML Injection in Knowledge Base (KB) articles lead…
Espocrm
9.0.8+
MEDIUM 6.5
CVE-2025-32385
EspoCRM is an Open Source Customer Relationship Management software. Prior to 9.0.5, Iframe dashlet allows user to display iframes with arbitrary URL…
Espocrm
9.0.5+
MEDIUM 5.9
CVE-2024-24818
EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "Password Change" page and redi…
Espocrm
8.1.2+
MEDIUM 6.5
CVE-2023-46736
EspoCRM is an Open Source CRM (Customer Relationship Management) software. In affected versions there is Server-Side Request Forgery (SSRF) vulnerabi…
Espocrm
after 8.0.2
HIGH 7.2
CVE-2023-5966
An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, …
Espocrm
after 7.5.2
HIGH 7.2
CVE-2023-5965
An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the update form, which could le…
Espocrm
after 7.5.2
HIGH 8.8
CVE-2022-38843
EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server. Attacke…
Espocrm
No fix yet
HIGH 8.0
CVE-2022-38844
CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloads capabl…
Espocrm
No fix yet
MEDIUM 6.1
CVE-2022-38845
Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending crafted csv f…
Espocrm
No fix yet
MEDIUM 5.9
CVE-2022-38846
EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attack…
Espocrm
No fix yet
MEDIUM 5.4
CVE-2021-3539
EspoCRM 6.1.6 and prior suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This …
Espocrm
after 6.1.6
MEDIUM 5.4
CVE-2019-14546
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending an email when a malicious pa…
Espocrm
5.6.9+
MEDIUM 5.4
CVE-2019-14547
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin with malicious JavaScript in th…
Espocrm
5.6.9+
MEDIUM 5.4
CVE-2019-14548
An issue was discovered in EspoCRM before 5.6.9. Stored XSS in the body of an Article was executed when a victim opens articles received through mail…
Espocrm
5.6.9+
MEDIUM 5.4
CVE-2019-14549
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed inside the title and breadcrumb of a newly formed entity available to all th…
Espocrm
5.6.9+
MEDIUM 5.4
CVE-2019-14550
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a victim clicks on the Edit Dashboard feature present on the Homepage. …
Espocrm
5.6.9+
HIGH 8.8
CVE-2019-14351
EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user password hash by 1 symbol at…
Espocrm
No fix yet
MEDIUM 6.1
CVE-2019-14349
EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for storing do…
Espocrm
No fix yet
MEDIUM 6.1
CVE-2019-14350
EspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base. A malicious attacker can inject Java…
Espocrm
No fix yet
MEDIUM 6.1
CVE-2019-14329
An issue was discovered in EspoCRM before 5.6.6. There is stored XSS due to lack of filtration of user-supplied data in Create Task. A malicious atta…
Espocrm
5.6.6+
MEDIUM 6.1
CVE-2019-14330
An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create Case. A malicious attack…
Espocrm
5.6.6+
MEDIUM 6.1
CVE-2019-14331
An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create User. A malicious attack…
Espocrm
5.6.6+