espocrm kayıtları
espocrm üreticisine ait 40 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %30
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')17
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-303 Incorrect Implementation of Authentication Algorithm1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
40 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2014-7985İstismar yok | Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local files via a ..espocrm · espocrm · CWE-22 | Kritik10,0 | — | %5,0 | 31 Eki 2014 |
36İzleyin | CVE-2026-33656Kavram kanıtı | EspoCRM vulnerable to authenticated RCE via Formula with path traversal in attachment `sourceId`, exploitable by admin userespocrm · espocrm · CWE-22 | Kritik9,1 | — | %0,6 | 22 Nis 2026 |
35İzleyin | CVE-2022-38843İstismar yok | EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the serverespocrm · espocrm · CWE-434 | Yüksek8,8 | — | %1,3 | 16 Eyl 2022 |
35İzleyin | CVE-2019-14351İstismar yok | EspoCRM 5.6.4 is vulnerable to user password hash enumeration.espocrm · espocrm · CWE-307 | Yüksek8,8 | — | %1,3 | 28 Tem 2019 |
34İzleyin | CVE-2020-37094İstismar yok | EspoCRM 5.7.0 < 5.9.0 - Two-Factor Authentication Bypass via Auth Token Reuse Between Accounts with Identical Passwordsespocrm · espocrm · CWE-303 | Yüksek8,6 | — | %0,5 | 3 Şub 2026 |
32İzleyin | CVE-2022-38844İstismar yok | CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloaespocrm · espocrm · CWE-1236 | Yüksek8,0 | — | %1,3 | 16 Eyl 2022 |
28İzleyin | CVE-2023-5966Kavram kanıtı | Unrestricted Upload of File with Dangerous Type in EspoCRMespocrm · espocrm · CWE-434 | Yüksek7,2 | — | %1,0 | 30 Kas 2023 |
28İzleyin | CVE-2023-5965Kavram kanıtı | Unrestricted Upload of File with Dangerous Type in EspoCRMespocrm · espocrm · CWE-434 | Yüksek7,2 | — | %1,0 | 30 Kas 2023 |
28İzleyin | CVE-2026-33733İstismar yok | EspoCRM has Admin TemplateManager path traversal that allows arbitrary file read write and deleteespocrm · espocrm · CWE-23 | Yüksek7,2 | — | %0,6 | 22 Nis 2026 |
28İzleyin | CVE-2025-32390İstismar yok | EspoCRM vulnerable to HTML Injection into phishing, which may lead to account takeoverespocrm · espocrm · CWE-74 | Yüksek7,0 | — | %0,4 | 12 May 2025 |
26İzleyin | CVE-2025-52575İstismar yok | EspoCRM vulnerable to LDAP Injection through Improper Neutralization of Special Elementsespocrm · espocrm · CWE-90 | Orta6,5 | — | %0,7 | 21 Tem 2025 |
26İzleyin | CVE-2023-46736İstismar yok | Server-Side Request Forgery in espocrmespocrm · espocrm · CWE-918 | Orta6,5 | — | %0,4 | 5 Ara 2023 |
26İzleyin | CVE-2025-32385İstismar yok | EspoCRM allows unrestricted Embedding in Iframe dashletespocrm · espocrm · CWE-1021 | Orta6,5 | — | %0,3 | 15 Nis 2025 |
26İzleyin | CVE-2025-52892İstismar yok | EspoCRM is vulnerable to access denial through double slash in URI corrupting router cacheespocrm · espocrm · CWE-444 | Orta6,5 | — | %0,2 | 4 Ağu 2025 |
24İzleyin | CVE-2019-14330İstismar yok | An issue was discovered in EspoCRM before 5.6.6.espocrm · espocrm · CWE-79 | Orta6,1 | — | %1,3 | 28 Tem 2019 |
24İzleyin | CVE-2019-14329İstismar yok | An issue was discovered in EspoCRM before 5.6.6.espocrm · espocrm · CWE-79 | Orta6,1 | — | %1,3 | 28 Tem 2019 |
24İzleyin | CVE-2019-14331İstismar yok | An issue was discovered in EspoCRM before 5.6.6.espocrm · espocrm · CWE-79 | Orta6,1 | — | %1,3 | 28 Tem 2019 |
24İzleyin | CVE-2019-13643İstismar yok | Stored XSS in EspoCRM before 5.6.4 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target espocrm · espocrm · CWE-79 | Orta6,1 | — | %1,1 | 17 Tem 2019 |
24İzleyin | CVE-2019-14349İstismar yok | EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for sespocrm · espocrm · CWE-79 | Orta6,1 | — | %0,9 | 28 Tem 2019 |
24İzleyin | CVE-2019-14350İstismar yok | EspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base.espocrm · espocrm · CWE-79 | Orta6,1 | — | %0,9 | 28 Tem 2019 |
24İzleyin | CVE-2022-38845İstismar yok | Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending crafespocrm · espocrm · CWE-79 | Orta6,1 | — | %0,7 | 16 Eyl 2022 |
23İzleyin | CVE-2024-24818İstismar yok | EspoCRM weakness in "Forgot password"espocrm · espocrm · CWE-610 | Orta5,9 | — | %0,6 | 20 Mar 2024 |
23İzleyin | CVE-2022-38846İstismar yok | EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP).espocrm · espocrm · CWE-319 | Orta5,9 | — | %0,5 | 16 Eyl 2022 |
21İzleyin | CVE-2014-7986İstismar yok | install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the installProcess parameteespocrm · espocrm · CWE-264 | Orta5,0 | — | %2,9 | 31 Eki 2014 |
21İzleyin | CVE-2019-14546İstismar yok | An issue was discovered in EspoCRM before 5.6.9.espocrm · espocrm · CWE-79 | Orta5,4 | — | %1,1 | 5 Ağu 2019 |
- CVE-2014-798542Planlayın
Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local files via a ..
KritikCVSS 10,0İstismar yokEPSS %5espocrm · espocrm31 Eki 2014
- CVE-2026-3365636İzleyin
EspoCRM vulnerable to authenticated RCE via Formula with path traversal in attachment `sourceId`, exploitable by admin user
KritikCVSS 9,1Kavram kanıtıEPSS %1espocrm · espocrm22 Nis 2026
- CVE-2022-3884335İzleyin
EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server
YüksekCVSS 8,8İstismar yokEPSS %1espocrm · espocrm16 Eyl 2022
- CVE-2019-1435135İzleyin
EspoCRM 5.6.4 is vulnerable to user password hash enumeration.
YüksekCVSS 8,8İstismar yokEPSS %1espocrm · espocrm28 Tem 2019
- CVE-2020-3709434İzleyin
EspoCRM 5.7.0 < 5.9.0 - Two-Factor Authentication Bypass via Auth Token Reuse Between Accounts with Identical Passwords
YüksekCVSS 8,6İstismar yokEPSS %0espocrm · espocrm3 Şub 2026
- CVE-2022-3884432İzleyin
CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloa
YüksekCVSS 8,0İstismar yokEPSS %1espocrm · espocrm16 Eyl 2022
- CVE-2023-596628İzleyin
Unrestricted Upload of File with Dangerous Type in EspoCRM
YüksekCVSS 7,2Kavram kanıtıEPSS %1espocrm · espocrm30 Kas 2023
- CVE-2023-596528İzleyin
Unrestricted Upload of File with Dangerous Type in EspoCRM
YüksekCVSS 7,2Kavram kanıtıEPSS %1espocrm · espocrm30 Kas 2023
- CVE-2026-3373328İzleyin
EspoCRM has Admin TemplateManager path traversal that allows arbitrary file read write and delete
YüksekCVSS 7,2İstismar yokEPSS %1espocrm · espocrm22 Nis 2026
- CVE-2025-3239028İzleyin
EspoCRM vulnerable to HTML Injection into phishing, which may lead to account takeover
YüksekCVSS 7,0İstismar yokEPSS %0espocrm · espocrm12 May 2025
- CVE-2025-5257526İzleyin
EspoCRM vulnerable to LDAP Injection through Improper Neutralization of Special Elements
OrtaCVSS 6,5İstismar yokEPSS %1espocrm · espocrm21 Tem 2025
- CVE-2023-4673626İzleyin
Server-Side Request Forgery in espocrm
OrtaCVSS 6,5İstismar yokEPSS %0espocrm · espocrm5 Ara 2023
- CVE-2025-3238526İzleyin
EspoCRM allows unrestricted Embedding in Iframe dashlet
OrtaCVSS 6,5İstismar yokEPSS %0espocrm · espocrm15 Nis 2025
- CVE-2025-5289226İzleyin
EspoCRM is vulnerable to access denial through double slash in URI corrupting router cache
OrtaCVSS 6,5İstismar yokEPSS %0espocrm · espocrm4 Ağu 2025
- CVE-2019-1433024İzleyin
An issue was discovered in EspoCRM before 5.6.6.
OrtaCVSS 6,1İstismar yokEPSS %1espocrm · espocrm28 Tem 2019
- CVE-2019-1432924İzleyin
An issue was discovered in EspoCRM before 5.6.6.
OrtaCVSS 6,1İstismar yokEPSS %1espocrm · espocrm28 Tem 2019
- CVE-2019-1433124İzleyin
An issue was discovered in EspoCRM before 5.6.6.
OrtaCVSS 6,1İstismar yokEPSS %1espocrm · espocrm28 Tem 2019
- CVE-2019-1364324İzleyin
Stored XSS in EspoCRM before 5.6.4 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target
OrtaCVSS 6,1İstismar yokEPSS %1espocrm · espocrm17 Tem 2019
- CVE-2019-1434924İzleyin
EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for s
OrtaCVSS 6,1İstismar yokEPSS %1espocrm · espocrm28 Tem 2019
- CVE-2019-1435024İzleyin
EspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base.
OrtaCVSS 6,1İstismar yokEPSS %1espocrm · espocrm28 Tem 2019
- CVE-2022-3884524İzleyin
Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending craf
OrtaCVSS 6,1İstismar yokEPSS %1espocrm · espocrm16 Eyl 2022
- CVE-2024-2481823İzleyin
EspoCRM weakness in "Forgot password"
OrtaCVSS 5,9İstismar yokEPSS %1espocrm · espocrm20 Mar 2024
- CVE-2022-3884623İzleyin
EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP).
OrtaCVSS 5,9İstismar yokEPSS %0espocrm · espocrm16 Eyl 2022
- CVE-2014-798621İzleyin
install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the installProcess paramete
OrtaCVSS 5,0İstismar yokEPSS %3espocrm · espocrm31 Eki 2014
- CVE-2019-1454621İzleyin
An issue was discovered in EspoCRM before 5.6.9.
OrtaCVSS 5,4İstismar yokEPSS %1espocrm · espocrm5 Ağu 2019