Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

X2crm MEDIUM 5.4
CVE-2024-48120

X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject malicious JavaScript code into …

No fix yet
Fix from $1,600 2024-10-14
X2crm MEDIUM 5.4
CVE-2022-48177

X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importModels Impo…

No fix yet
Fix from $1,600 2023-04-15
X2crm MEDIUM 5.4
CVE-2022-48178

X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action function, a…

No fix yet
Fix from $1,600 2023-04-15
X2crm MEDIUM 5.4
CVE-2021-33853

A Cross-Site Scripting (XSS) attack can cause arbitrary code (javascript) to run in a user’s browser while the browser is connected to a trusted webs…

No fix yet
Fix from $1,600 2022-03-16
X2crm MEDIUM 6.1
CVE-2020-21087

Cross Site Scripting (XSS) in X2Engine X2CRM v6.9 and older allows remote attackers to execute arbitrary code by injecting arbitrary web script or HT…

Fix: after 6.9
Fix from $1,600 2021-04-14
X2crm MEDIUM 6.1
CVE-2021-27288

Cross Site Scripting (XSS) in X2Engine X2CRM v7.1 allows remote attackers to obtain sensitive information by injecting arbitrary web script or HTML v…

No fix yet
Fix from $1,600 2021-04-14
X2crm HIGH 8.8
CVE-2014-2664

Unrestricted file upload vulnerability in the ProfileController::actionUploadPhoto method in protected/controllers/ProfileController.php in X2Engine …

Fix: after 3.7.5
Fix from $1,950 2017-10-17
X2crm MEDIUM 6.8
CVE-2015-5075

Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authentication of administrators f…

Fix: after 5.0.9
Fix from $1,600 2015-09-29
X2crm HIGH 7.5
CVE-2015-5074EPSS 8%

Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php in X2Engine X2CRM before 5.0.…

Fix: after 5.0.8
Fix from $1,950 2015-09-29
X2engine HIGH 7.5
CVE-2014-5297

The actionSendErrorReport method in protected/controllers/SiteController.php in X2Engine 2.8 through 4.1.7 allows remote attackers to conduct PHP obj…

Patch available
Fix from $1,950 2014-10-10
X2engine MEDIUM 5.0
CVE-2014-5298

FileUploadsFilter.php in X2Engine 4.1.7 and earlier, when running on case-insensitive file systems, allows remote attackers to bypass the upload blac…

Fix: after 4.1.7
Fix from $1,600 2014-10-10
X2crm HIGH 8.5
CVE-2013-5692EPSS 6%

Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary local file…

Fix: after 3.4.1
Fix from $1,950 2013-09-30