Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2024-48120 X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject malicious JavaScript code into … X2crm No fix yet Fix from $1,6002024-10-14 MEDIUM 5.4 CVE-2022-48177 X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importModels Impo… X2crm No fix yet Fix from $1,6002023-04-15 MEDIUM 5.4 CVE-2022-48178 X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action function, a… X2crm No fix yet Fix from $1,6002023-04-15 MEDIUM 5.4 CVE-2021-33853 A Cross-Site Scripting (XSS) attack can cause arbitrary code (javascript) to run in a user’s browser while the browser is connected to a trusted webs… X2crm No fix yet Fix from $1,6002022-03-16 MEDIUM 6.1 CVE-2020-21087 Cross Site Scripting (XSS) in X2Engine X2CRM v6.9 and older allows remote attackers to execute arbitrary code by injecting arbitrary web script or HT… X2crm after 6.9 Fix from $1,6002021-04-14 MEDIUM 6.1 CVE-2021-27288 Cross Site Scripting (XSS) in X2Engine X2CRM v7.1 allows remote attackers to obtain sensitive information by injecting arbitrary web script or HTML v… X2crm No fix yet Fix from $1,6002021-04-14 HIGH 8.8 CVE-2014-2664 Unrestricted file upload vulnerability in the ProfileController::actionUploadPhoto method in protected/controllers/ProfileController.php in X2Engine … X2crm after 3.7.5 Fix from $1,9502017-10-17 MEDIUM 6.8 CVE-2015-5075 Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authentication of administrators f… X2crm after 5.0.9 Fix from $1,6002015-09-29 HIGH 7.5 CVE-2015-5074EPSS 8% Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php in X2Engine X2CRM before 5.0.… X2crm after 5.0.8 Fix from $1,9502015-09-29 HIGH 7.5 CVE-2014-5297 The actionSendErrorReport method in protected/controllers/SiteController.php in X2Engine 2.8 through 4.1.7 allows remote attackers to conduct PHP obj… X2engine Patch available Fix from $1,9502014-10-10 MEDIUM 5.0 CVE-2014-5298 FileUploadsFilter.php in X2Engine 4.1.7 and earlier, when running on case-insensitive file systems, allows remote attackers to bypass the upload blac… X2engine after 4.1.7 Fix from $1,6002014-10-10 HIGH 8.5 CVE-2013-5692EPSS 6% Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary local file… X2crm after 3.4.1 Fix from $1,9502013-09-30