Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-33656 EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing … Espocrm 9.3.4+ Fix from $2,3002026-04-22 HIGH 7.2 CVE-2026-33733 EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template management endpoints accept attack… Espocrm 9.3.4+ Fix from $1,9502026-04-22 MEDIUM 5.4 CVE-2026-33740 EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Email/importEml endpoint contai… Espocrm 9.3.4+ Fix from $1,6002026-04-13 MEDIUM 5.4 CVE-2026-33657 EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML injection vulnerability that allo… Espocrm 9.3.4+ Fix from $1,6002026-04-13 HIGH 8.1 CVE-2020-37094 EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to bypass two-factor authentica… Espocrm after 5.8.5 Fix from $1,9502026-02-03 MEDIUM 5.4 CVE-2025-59428 EspoCRM is an open source customer relationship management application. In versions before 9.1.9, a vulnerability allows arbitrary user creation, inc… Espocrm 9.1.9+ Fix from $1,6002025-10-14 MEDIUM 6.5 CVE-2025-52892 EspoCRM is a web application with a frontend designed as a single-page application and a REST API backend written in PHP. In versions 9.1.6 and below… Espocrm 9.1.7+ Fix from $1,6002025-08-05 MEDIUM 6.5 CVE-2025-52575 EspoCRM is an Open Source CRM (Customer Relationship Management) software. EspoCRM versions 9.1.6 and earlier are vulnerable to blind LDAP Injection … Espocrm 9.1.7+ Fix from $1,6002025-07-21 HIGH 8.5 CVE-2025-32390 EspoCRM is a free, open-source customer relationship management platform. Prior to version 9.0.8, HTML Injection in Knowledge Base (KB) articles lead… Espocrm 9.0.8+ Fix from $1,9502025-05-12 MEDIUM 6.5 CVE-2025-32385 EspoCRM is an Open Source Customer Relationship Management software. Prior to 9.0.5, Iframe dashlet allows user to display iframes with arbitrary URL… Espocrm 9.0.5+ Fix from $1,6002025-04-16 MEDIUM 5.9 CVE-2024-24818 EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "Password Change" page and redi… Espocrm 8.1.2+ Fix from $1,6002024-03-21 MEDIUM 6.5 CVE-2023-46736 EspoCRM is an Open Source CRM (Customer Relationship Management) software. In affected versions there is Server-Side Request Forgery (SSRF) vulnerabi… Espocrm after 8.0.2 Fix from $1,6002023-12-05 HIGH 7.2 CVE-2023-5966 An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, … Espocrm after 7.5.2 Fix from $1,9502023-11-30 HIGH 7.2 CVE-2023-5965 An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the update form, which could le… Espocrm after 7.5.2 Fix from $1,9502023-11-30 HIGH 8.8 CVE-2022-38843 EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server. Attacke… Espocrm No fix yet Fix from $1,9502022-09-16 HIGH 8.0 CVE-2022-38844 CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloads capabl… Espocrm No fix yet Fix from $1,9502022-09-16 MEDIUM 6.1 CVE-2022-38845 Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending crafted csv f… Espocrm No fix yet Fix from $1,6002022-09-16 MEDIUM 5.9 CVE-2022-38846 EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attack… Espocrm No fix yet Fix from $1,6002022-09-16 MEDIUM 5.4 CVE-2021-3539 EspoCRM 6.1.6 and prior suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This … Espocrm after 6.1.6 Fix from $1,6002021-08-04 MEDIUM 5.4 CVE-2019-14546 An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending an email when a malicious pa… Espocrm 5.6.9+ Fix from $1,6002019-08-05 MEDIUM 5.4 CVE-2019-14547 An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin with malicious JavaScript in th… Espocrm 5.6.9+ Fix from $1,6002019-08-05 MEDIUM 5.4 CVE-2019-14548 An issue was discovered in EspoCRM before 5.6.9. Stored XSS in the body of an Article was executed when a victim opens articles received through mail… Espocrm 5.6.9+ Fix from $1,6002019-08-05 MEDIUM 5.4 CVE-2019-14549 An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed inside the title and breadcrumb of a newly formed entity available to all th… Espocrm 5.6.9+ Fix from $1,6002019-08-05 MEDIUM 5.4 CVE-2019-14550 An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a victim clicks on the Edit Dashboard feature present on the Homepage. … Espocrm 5.6.9+ Fix from $1,6002019-08-05 HIGH 8.8 CVE-2019-14351 EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user password hash by 1 symbol at… Espocrm No fix yet Fix from $1,9502019-07-28 MEDIUM 6.1 CVE-2019-14349 EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for storing do… Espocrm No fix yet Fix from $1,6002019-07-28 MEDIUM 6.1 CVE-2019-14350 EspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base. A malicious attacker can inject Java… Espocrm No fix yet Fix from $1,6002019-07-28 MEDIUM 6.1 CVE-2019-14329 An issue was discovered in EspoCRM before 5.6.6. There is stored XSS due to lack of filtration of user-supplied data in Create Task. A malicious atta… Espocrm 5.6.6+ Fix from $1,6002019-07-28 MEDIUM 6.1 CVE-2019-14330 An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create Case. A malicious attack… Espocrm 5.6.6+ Fix from $1,6002019-07-28 MEDIUM 6.1 CVE-2019-14331 An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create User. A malicious attack… Espocrm 5.6.6+ Fix from $1,6002019-07-28