Skip to content
Noroxi

espocrm records

40 published records for vendor espocrm.

All records

40 records
  • Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local files via a ..

    CriticalCVSS 10.0No exploitEPSS 5%

    espocrm · espocrmOct 31, 2014

  • EspoCRM vulnerable to authenticated RCE via Formula with path traversal in attachment `sourceId`, exploitable by admin user

    CriticalCVSS 9.1Proof of conceptEPSS 1%

    espocrm · espocrmApr 22, 2026

  • EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server

    HighCVSS 8.8No exploitEPSS 1%

    espocrm · espocrmSep 16, 2022

  • EspoCRM 5.6.4 is vulnerable to user password hash enumeration.

    HighCVSS 8.8No exploitEPSS 1%

    espocrm · espocrmJul 28, 2019

  • EspoCRM 5.7.0 < 5.9.0 - Two-Factor Authentication Bypass via Auth Token Reuse Between Accounts with Identical Passwords

    HighCVSS 8.6No exploitEPSS 0%

    espocrm · espocrmFeb 3, 2026

  • CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloa

    HighCVSS 8.0No exploitEPSS 1%

    espocrm · espocrmSep 16, 2022

  • CVE-2023-5966
    28Monitor

    Unrestricted Upload of File with Dangerous Type in EspoCRM

    HighCVSS 7.2Proof of conceptEPSS 1%

    espocrm · espocrmNov 30, 2023

  • CVE-2023-5965
    28Monitor

    Unrestricted Upload of File with Dangerous Type in EspoCRM

    HighCVSS 7.2Proof of conceptEPSS 1%

    espocrm · espocrmNov 30, 2023

  • EspoCRM has Admin TemplateManager path traversal that allows arbitrary file read write and delete

    HighCVSS 7.2No exploitEPSS 1%

    espocrm · espocrmApr 22, 2026

  • EspoCRM vulnerable to HTML Injection into phishing, which may lead to account takeover

    HighCVSS 7.0No exploitEPSS 0%

    espocrm · espocrmMay 12, 2025

  • EspoCRM vulnerable to LDAP Injection through Improper Neutralization of Special Elements

    MediumCVSS 6.5No exploitEPSS 1%

    espocrm · espocrmJul 21, 2025

  • Server-Side Request Forgery in espocrm

    MediumCVSS 6.5No exploitEPSS 0%

    espocrm · espocrmDec 5, 2023

  • EspoCRM allows unrestricted Embedding in Iframe dashlet

    MediumCVSS 6.5No exploitEPSS 0%

    espocrm · espocrmApr 15, 2025

  • EspoCRM is vulnerable to access denial through double slash in URI corrupting router cache

    MediumCVSS 6.5No exploitEPSS 0%

    espocrm · espocrmAug 4, 2025

  • An issue was discovered in EspoCRM before 5.6.6.

    MediumCVSS 6.1No exploitEPSS 1%

    espocrm · espocrmJul 28, 2019

  • An issue was discovered in EspoCRM before 5.6.6.

    MediumCVSS 6.1No exploitEPSS 1%

    espocrm · espocrmJul 28, 2019

  • An issue was discovered in EspoCRM before 5.6.6.

    MediumCVSS 6.1No exploitEPSS 1%

    espocrm · espocrmJul 28, 2019

  • Stored XSS in EspoCRM before 5.6.4 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target

    MediumCVSS 6.1No exploitEPSS 1%

    espocrm · espocrmJul 17, 2019

  • EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for s

    MediumCVSS 6.1No exploitEPSS 1%

    espocrm · espocrmJul 28, 2019

  • EspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base.

    MediumCVSS 6.1No exploitEPSS 1%

    espocrm · espocrmJul 28, 2019

  • Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending craf

    MediumCVSS 6.1No exploitEPSS 1%

    espocrm · espocrmSep 16, 2022

  • EspoCRM weakness in "Forgot password"

    MediumCVSS 5.9No exploitEPSS 1%

    espocrm · espocrmMar 20, 2024

  • EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP).

    MediumCVSS 5.9No exploitEPSS 0%

    espocrm · espocrmSep 16, 2022

  • CVE-2014-7986
    21Monitor

    install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the installProcess paramete

    MediumCVSS 5.0No exploitEPSS 3%

    espocrm · espocrmOct 31, 2014

  • An issue was discovered in EspoCRM before 5.6.9.

    MediumCVSS 5.4No exploitEPSS 1%

    espocrm · espocrmAug 5, 2019