espocrm records
40 published records for vendor espocrm.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 30%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')17
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-303 Incorrect Implementation of Authentication Algorithm1
The weakness classes this vendor ships most often: where to look.
CWEAll records
40 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2014-7985No exploit | Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local files via a ..espocrm · espocrm · CWE-22 | Critical10.0 | — | 5.0% | Oct 31, 2014 |
36Monitor | CVE-2026-33656Proof of concept | EspoCRM vulnerable to authenticated RCE via Formula with path traversal in attachment `sourceId`, exploitable by admin userespocrm · espocrm · CWE-22 | Critical9.1 | — | 0.6% | Apr 22, 2026 |
35Monitor | CVE-2022-38843No exploit | EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the serverespocrm · espocrm · CWE-434 | High8.8 | — | 1.3% | Sep 16, 2022 |
35Monitor | CVE-2019-14351No exploit | EspoCRM 5.6.4 is vulnerable to user password hash enumeration.espocrm · espocrm · CWE-307 | High8.8 | — | 1.3% | Jul 28, 2019 |
34Monitor | CVE-2020-37094No exploit | EspoCRM 5.7.0 < 5.9.0 - Two-Factor Authentication Bypass via Auth Token Reuse Between Accounts with Identical Passwordsespocrm · espocrm · CWE-303 | High8.6 | — | 0.5% | Feb 3, 2026 |
32Monitor | CVE-2022-38844No exploit | CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloaespocrm · espocrm · CWE-1236 | High8.0 | — | 1.3% | Sep 16, 2022 |
28Monitor | CVE-2023-5966Proof of concept | Unrestricted Upload of File with Dangerous Type in EspoCRMespocrm · espocrm · CWE-434 | High7.2 | — | 1.0% | Nov 30, 2023 |
28Monitor | CVE-2023-5965Proof of concept | Unrestricted Upload of File with Dangerous Type in EspoCRMespocrm · espocrm · CWE-434 | High7.2 | — | 1.0% | Nov 30, 2023 |
28Monitor | CVE-2026-33733No exploit | EspoCRM has Admin TemplateManager path traversal that allows arbitrary file read write and deleteespocrm · espocrm · CWE-23 | High7.2 | — | 0.6% | Apr 22, 2026 |
28Monitor | CVE-2025-32390No exploit | EspoCRM vulnerable to HTML Injection into phishing, which may lead to account takeoverespocrm · espocrm · CWE-74 | High7.0 | — | 0.4% | May 12, 2025 |
26Monitor | CVE-2025-52575No exploit | EspoCRM vulnerable to LDAP Injection through Improper Neutralization of Special Elementsespocrm · espocrm · CWE-90 | Medium6.5 | — | 0.7% | Jul 21, 2025 |
26Monitor | CVE-2023-46736No exploit | Server-Side Request Forgery in espocrmespocrm · espocrm · CWE-918 | Medium6.5 | — | 0.4% | Dec 5, 2023 |
26Monitor | CVE-2025-32385No exploit | EspoCRM allows unrestricted Embedding in Iframe dashletespocrm · espocrm · CWE-1021 | Medium6.5 | — | 0.3% | Apr 15, 2025 |
26Monitor | CVE-2025-52892No exploit | EspoCRM is vulnerable to access denial through double slash in URI corrupting router cacheespocrm · espocrm · CWE-444 | Medium6.5 | — | 0.2% | Aug 4, 2025 |
24Monitor | CVE-2019-14330No exploit | An issue was discovered in EspoCRM before 5.6.6.espocrm · espocrm · CWE-79 | Medium6.1 | — | 1.3% | Jul 28, 2019 |
24Monitor | CVE-2019-14329No exploit | An issue was discovered in EspoCRM before 5.6.6.espocrm · espocrm · CWE-79 | Medium6.1 | — | 1.3% | Jul 28, 2019 |
24Monitor | CVE-2019-14331No exploit | An issue was discovered in EspoCRM before 5.6.6.espocrm · espocrm · CWE-79 | Medium6.1 | — | 1.3% | Jul 28, 2019 |
24Monitor | CVE-2019-13643No exploit | Stored XSS in EspoCRM before 5.6.4 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target espocrm · espocrm · CWE-79 | Medium6.1 | — | 1.1% | Jul 17, 2019 |
24Monitor | CVE-2019-14349No exploit | EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for sespocrm · espocrm · CWE-79 | Medium6.1 | — | 0.9% | Jul 28, 2019 |
24Monitor | CVE-2019-14350No exploit | EspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base.espocrm · espocrm · CWE-79 | Medium6.1 | — | 0.9% | Jul 28, 2019 |
24Monitor | CVE-2022-38845No exploit | Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending crafespocrm · espocrm · CWE-79 | Medium6.1 | — | 0.7% | Sep 16, 2022 |
23Monitor | CVE-2024-24818No exploit | EspoCRM weakness in "Forgot password"espocrm · espocrm · CWE-610 | Medium5.9 | — | 0.6% | Mar 20, 2024 |
23Monitor | CVE-2022-38846No exploit | EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP).espocrm · espocrm · CWE-319 | Medium5.9 | — | 0.5% | Sep 16, 2022 |
21Monitor | CVE-2014-7986No exploit | install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the installProcess parameteespocrm · espocrm · CWE-264 | Medium5.0 | — | 2.9% | Oct 31, 2014 |
21Monitor | CVE-2019-14546No exploit | An issue was discovered in EspoCRM before 5.6.9.espocrm · espocrm · CWE-79 | Medium5.4 | — | 1.1% | Aug 5, 2019 |
- CVE-2014-798542Plan
Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local files via a ..
CriticalCVSS 10.0No exploitEPSS 5%espocrm · espocrmOct 31, 2014
- CVE-2026-3365636Monitor
EspoCRM vulnerable to authenticated RCE via Formula with path traversal in attachment `sourceId`, exploitable by admin user
CriticalCVSS 9.1Proof of conceptEPSS 1%espocrm · espocrmApr 22, 2026
- CVE-2022-3884335Monitor
EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server
HighCVSS 8.8No exploitEPSS 1%espocrm · espocrmSep 16, 2022
- CVE-2019-1435135Monitor
EspoCRM 5.6.4 is vulnerable to user password hash enumeration.
HighCVSS 8.8No exploitEPSS 1%espocrm · espocrmJul 28, 2019
- CVE-2020-3709434Monitor
EspoCRM 5.7.0 < 5.9.0 - Two-Factor Authentication Bypass via Auth Token Reuse Between Accounts with Identical Passwords
HighCVSS 8.6No exploitEPSS 0%espocrm · espocrmFeb 3, 2026
- CVE-2022-3884432Monitor
CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloa
HighCVSS 8.0No exploitEPSS 1%espocrm · espocrmSep 16, 2022
- CVE-2023-596628Monitor
Unrestricted Upload of File with Dangerous Type in EspoCRM
HighCVSS 7.2Proof of conceptEPSS 1%espocrm · espocrmNov 30, 2023
- CVE-2023-596528Monitor
Unrestricted Upload of File with Dangerous Type in EspoCRM
HighCVSS 7.2Proof of conceptEPSS 1%espocrm · espocrmNov 30, 2023
- CVE-2026-3373328Monitor
EspoCRM has Admin TemplateManager path traversal that allows arbitrary file read write and delete
HighCVSS 7.2No exploitEPSS 1%espocrm · espocrmApr 22, 2026
- CVE-2025-3239028Monitor
EspoCRM vulnerable to HTML Injection into phishing, which may lead to account takeover
HighCVSS 7.0No exploitEPSS 0%espocrm · espocrmMay 12, 2025
- CVE-2025-5257526Monitor
EspoCRM vulnerable to LDAP Injection through Improper Neutralization of Special Elements
MediumCVSS 6.5No exploitEPSS 1%espocrm · espocrmJul 21, 2025
- CVE-2023-4673626Monitor
Server-Side Request Forgery in espocrm
MediumCVSS 6.5No exploitEPSS 0%espocrm · espocrmDec 5, 2023
- CVE-2025-3238526Monitor
EspoCRM allows unrestricted Embedding in Iframe dashlet
MediumCVSS 6.5No exploitEPSS 0%espocrm · espocrmApr 15, 2025
- CVE-2025-5289226Monitor
EspoCRM is vulnerable to access denial through double slash in URI corrupting router cache
MediumCVSS 6.5No exploitEPSS 0%espocrm · espocrmAug 4, 2025
- CVE-2019-1433024Monitor
An issue was discovered in EspoCRM before 5.6.6.
MediumCVSS 6.1No exploitEPSS 1%espocrm · espocrmJul 28, 2019
- CVE-2019-1432924Monitor
An issue was discovered in EspoCRM before 5.6.6.
MediumCVSS 6.1No exploitEPSS 1%espocrm · espocrmJul 28, 2019
- CVE-2019-1433124Monitor
An issue was discovered in EspoCRM before 5.6.6.
MediumCVSS 6.1No exploitEPSS 1%espocrm · espocrmJul 28, 2019
- CVE-2019-1364324Monitor
Stored XSS in EspoCRM before 5.6.4 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target
MediumCVSS 6.1No exploitEPSS 1%espocrm · espocrmJul 17, 2019
- CVE-2019-1434924Monitor
EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for s
MediumCVSS 6.1No exploitEPSS 1%espocrm · espocrmJul 28, 2019
- CVE-2019-1435024Monitor
EspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base.
MediumCVSS 6.1No exploitEPSS 1%espocrm · espocrmJul 28, 2019
- CVE-2022-3884524Monitor
Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending craf
MediumCVSS 6.1No exploitEPSS 1%espocrm · espocrmSep 16, 2022
- CVE-2024-2481823Monitor
EspoCRM weakness in "Forgot password"
MediumCVSS 5.9No exploitEPSS 1%espocrm · espocrmMar 20, 2024
- CVE-2022-3884623Monitor
EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP).
MediumCVSS 5.9No exploitEPSS 0%espocrm · espocrmSep 16, 2022
- CVE-2014-798621Monitor
install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the installProcess paramete
MediumCVSS 5.0No exploitEPSS 3%espocrm · espocrmOct 31, 2014
- CVE-2019-1454621Monitor
An issue was discovered in EspoCRM before 5.6.9.
MediumCVSS 5.4No exploitEPSS 1%espocrm · espocrmAug 5, 2019