Skip to content
Noroxi

x2engine records

15 published records for vendor x2engine.

All records

15 records
  • CVE-2013-5692
    36Monitor

    Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary l

    HighCVSS 8.5Proof of conceptEPSS 6%

    x2engine · x2crmSep 30, 2013

  • CVE-2014-2664
    36Monitor

    Unrestricted file upload vulnerability in the ProfileController::actionUploadPhoto method in protected/controllers/ProfileController.php in

    HighCVSS 8.8No exploitEPSS 3%

    x2engine · x2crmOct 17, 2017

  • CVE-2015-5074
    32Monitor

    Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php in X2Engine X2CRM be

    HighCVSS 7.5Proof of conceptEPSS 8%

    x2engine · x2crmSep 29, 2015

  • CVE-2014-5297
    31Monitor

    The actionSendErrorReport method in protected/controllers/SiteController.php in X2Engine 2.8 through 4.1.7 allows remote attackers to conduc

    HighCVSS 7.5No exploitEPSS 3%

    x2engine · x2engineOct 9, 2014

  • CVE-2015-5075
    28Monitor

    Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authentication of adminis

    MediumCVSS 6.8Proof of conceptEPSS 3%

    x2engine · x2crmSep 29, 2015

  • Cross Site Scripting (XSS) in X2Engine X2CRM v6.9 and older allows remote attackers to execute arbitrary code by injecting arbitrary web scr

    MediumCVSS 6.1No exploitEPSS 1%

    x2engine · x2crmApr 14, 2021

  • Cross Site Scripting (XSS) in X2Engine X2CRM v7.1 allows remote attackers to obtain sensitive information by injecting arbitrary web script

    MediumCVSS 6.1No exploitEPSS 1%

    x2engine · x2crmApr 14, 2021

  • X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action fu

    MediumCVSS 5.4Proof of conceptEPSS 2%

    x2engine · x2crmApr 14, 2023

  • X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importMo

    MediumCVSS 5.4Proof of conceptEPSS 2%

    x2engine · x2crmApr 14, 2023

  • CVE-2014-5298
    21Monitor

    FileUploadsFilter.php in X2Engine 4.1.7 and earlier, when running on case-insensitive file systems, allows remote attackers to bypass the up

    MediumCVSS 5.0No exploitEPSS 3%

    x2engine · x2engineOct 9, 2014

  • X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module.

    MediumCVSS 5.4Proof of conceptEPSS 1%

    x2engine · x2crmOct 14, 2024

  • A Cross-Site Scripting (XSS) attack can cause arbitrary code (javascript) to run in a user’s browser while the browser is connected to a tru

    MediumCVSS 5.4No exploitEPSS 1%

    x2engine · x2crmMar 16, 2022

  • Cross Site Scripting (XSS) in X2engine X2CRM v7.1 and older allows remote attackers to obtain sensitive information by injecting arbitrary w

    MediumCVSS 4.8No exploitEPSS 1%

    x2engine · x2crmApr 14, 2021

  • CVE-2013-5693
    18Monitor

    Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web script or HTML via the

    MediumCVSS 4.3Proof of conceptEPSS 3%

    x2engine · x2crmSep 30, 2013

  • CVE-2015-5076
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in X2Engine X2CRM before 5.0.9 allow remote attackers to inject arbitrary web script or

    MediumCVSS 4.3No exploitEPSS 2%

    x2engine · x2crmSep 29, 2015