Перейти к содержимому
Noroxi

Записи espocrm

40 опубликованных записей вендора espocrm.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
1
С записью об исправлении
30 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

40 записей
  • CVE-2014-7985
    42В плане

    Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local files via a ..

    КритическаяCVSS 10,0Эксплойта нетEPSS 5 %

    espocrm · espocrm31 окт. 2014 г.

  • CVE-2026-33656
    36Наблюдать

    EspoCRM vulnerable to authenticated RCE via Formula with path traversal in attachment `sourceId`, exploitable by admin user

    КритическаяCVSS 9,1Proof of conceptEPSS 1 %

    espocrm · espocrm22 апр. 2026 г.

  • CVE-2022-38843
    35Наблюдать

    EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    espocrm · espocrm16 сент. 2022 г.

  • CVE-2019-14351
    35Наблюдать

    EspoCRM 5.6.4 is vulnerable to user password hash enumeration.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    espocrm · espocrm28 июл. 2019 г.

  • CVE-2020-37094
    34Наблюдать

    EspoCRM 5.7.0 < 5.9.0 - Two-Factor Authentication Bypass via Auth Token Reuse Between Accounts with Identical Passwords

    ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %

    espocrm · espocrm3 февр. 2026 г.

  • CVE-2022-38844
    32Наблюдать

    CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloa

    ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %

    espocrm · espocrm16 сент. 2022 г.

  • CVE-2023-5966
    28Наблюдать

    Unrestricted Upload of File with Dangerous Type in EspoCRM

    ВысокаяCVSS 7,2Proof of conceptEPSS 1 %

    espocrm · espocrm30 нояб. 2023 г.

  • CVE-2023-5965
    28Наблюдать

    Unrestricted Upload of File with Dangerous Type in EspoCRM

    ВысокаяCVSS 7,2Proof of conceptEPSS 1 %

    espocrm · espocrm30 нояб. 2023 г.

  • CVE-2026-33733
    28Наблюдать

    EspoCRM has Admin TemplateManager path traversal that allows arbitrary file read write and delete

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    espocrm · espocrm22 апр. 2026 г.

  • CVE-2025-32390
    28Наблюдать

    EspoCRM vulnerable to HTML Injection into phishing, which may lead to account takeover

    ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %

    espocrm · espocrm12 мая 2025 г.

  • CVE-2025-52575
    26Наблюдать

    EspoCRM vulnerable to LDAP Injection through Improper Neutralization of Special Elements

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    espocrm · espocrm21 июл. 2025 г.

  • CVE-2023-46736
    26Наблюдать

    Server-Side Request Forgery in espocrm

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    espocrm · espocrm5 дек. 2023 г.

  • CVE-2025-32385
    26Наблюдать

    EspoCRM allows unrestricted Embedding in Iframe dashlet

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    espocrm · espocrm15 апр. 2025 г.

  • CVE-2025-52892
    26Наблюдать

    EspoCRM is vulnerable to access denial through double slash in URI corrupting router cache

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    espocrm · espocrm4 авг. 2025 г.

  • CVE-2019-14330
    24Наблюдать

    An issue was discovered in EspoCRM before 5.6.6.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    espocrm · espocrm28 июл. 2019 г.

  • CVE-2019-14329
    24Наблюдать

    An issue was discovered in EspoCRM before 5.6.6.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    espocrm · espocrm28 июл. 2019 г.

  • CVE-2019-14331
    24Наблюдать

    An issue was discovered in EspoCRM before 5.6.6.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    espocrm · espocrm28 июл. 2019 г.

  • CVE-2019-13643
    24Наблюдать

    Stored XSS in EspoCRM before 5.6.4 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    espocrm · espocrm17 июл. 2019 г.

  • CVE-2019-14349
    24Наблюдать

    EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for s

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    espocrm · espocrm28 июл. 2019 г.

  • CVE-2019-14350
    24Наблюдать

    EspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    espocrm · espocrm28 июл. 2019 г.

  • CVE-2022-38845
    24Наблюдать

    Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending craf

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    espocrm · espocrm16 сент. 2022 г.

  • CVE-2024-24818
    23Наблюдать

    EspoCRM weakness in "Forgot password"

    СредняяCVSS 5,9Эксплойта нетEPSS 1 %

    espocrm · espocrm20 мар. 2024 г.

  • CVE-2022-38846
    23Наблюдать

    EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP).

    СредняяCVSS 5,9Эксплойта нетEPSS 0 %

    espocrm · espocrm16 сент. 2022 г.

  • CVE-2014-7986
    21Наблюдать

    install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the installProcess paramete

    СредняяCVSS 5,0Эксплойта нетEPSS 3 %

    espocrm · espocrm31 окт. 2014 г.

  • CVE-2019-14546
    21Наблюдать

    An issue was discovered in EspoCRM before 5.6.9.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    espocrm · espocrm5 авг. 2019 г.