İçeriğe atla
Noroxi

espocrm kayıtları

espocrm üreticisine ait 40 yayımlanmış kayıt.

Tüm kayıtlar

40 kayıt
  • CVE-2014-7985
    42Planlayın

    Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local files via a ..

    KritikCVSS 10,0İstismar yokEPSS %5

    espocrm · espocrm31 Eki 2014

  • CVE-2026-33656
    36İzleyin

    EspoCRM vulnerable to authenticated RCE via Formula with path traversal in attachment `sourceId`, exploitable by admin user

    KritikCVSS 9,1Kavram kanıtıEPSS %1

    espocrm · espocrm22 Nis 2026

  • CVE-2022-38843
    35İzleyin

    EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server

    YüksekCVSS 8,8İstismar yokEPSS %1

    espocrm · espocrm16 Eyl 2022

  • CVE-2019-14351
    35İzleyin

    EspoCRM 5.6.4 is vulnerable to user password hash enumeration.

    YüksekCVSS 8,8İstismar yokEPSS %1

    espocrm · espocrm28 Tem 2019

  • CVE-2020-37094
    34İzleyin

    EspoCRM 5.7.0 < 5.9.0 - Two-Factor Authentication Bypass via Auth Token Reuse Between Accounts with Identical Passwords

    YüksekCVSS 8,6İstismar yokEPSS %0

    espocrm · espocrm3 Şub 2026

  • CVE-2022-38844
    32İzleyin

    CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloa

    YüksekCVSS 8,0İstismar yokEPSS %1

    espocrm · espocrm16 Eyl 2022

  • CVE-2023-5966
    28İzleyin

    Unrestricted Upload of File with Dangerous Type in EspoCRM

    YüksekCVSS 7,2Kavram kanıtıEPSS %1

    espocrm · espocrm30 Kas 2023

  • CVE-2023-5965
    28İzleyin

    Unrestricted Upload of File with Dangerous Type in EspoCRM

    YüksekCVSS 7,2Kavram kanıtıEPSS %1

    espocrm · espocrm30 Kas 2023

  • CVE-2026-33733
    28İzleyin

    EspoCRM has Admin TemplateManager path traversal that allows arbitrary file read write and delete

    YüksekCVSS 7,2İstismar yokEPSS %1

    espocrm · espocrm22 Nis 2026

  • CVE-2025-32390
    28İzleyin

    EspoCRM vulnerable to HTML Injection into phishing, which may lead to account takeover

    YüksekCVSS 7,0İstismar yokEPSS %0

    espocrm · espocrm12 May 2025

  • CVE-2025-52575
    26İzleyin

    EspoCRM vulnerable to LDAP Injection through Improper Neutralization of Special Elements

    OrtaCVSS 6,5İstismar yokEPSS %1

    espocrm · espocrm21 Tem 2025

  • CVE-2023-46736
    26İzleyin

    Server-Side Request Forgery in espocrm

    OrtaCVSS 6,5İstismar yokEPSS %0

    espocrm · espocrm5 Ara 2023

  • CVE-2025-32385
    26İzleyin

    EspoCRM allows unrestricted Embedding in Iframe dashlet

    OrtaCVSS 6,5İstismar yokEPSS %0

    espocrm · espocrm15 Nis 2025

  • CVE-2025-52892
    26İzleyin

    EspoCRM is vulnerable to access denial through double slash in URI corrupting router cache

    OrtaCVSS 6,5İstismar yokEPSS %0

    espocrm · espocrm4 Ağu 2025

  • CVE-2019-14330
    24İzleyin

    An issue was discovered in EspoCRM before 5.6.6.

    OrtaCVSS 6,1İstismar yokEPSS %1

    espocrm · espocrm28 Tem 2019

  • CVE-2019-14329
    24İzleyin

    An issue was discovered in EspoCRM before 5.6.6.

    OrtaCVSS 6,1İstismar yokEPSS %1

    espocrm · espocrm28 Tem 2019

  • CVE-2019-14331
    24İzleyin

    An issue was discovered in EspoCRM before 5.6.6.

    OrtaCVSS 6,1İstismar yokEPSS %1

    espocrm · espocrm28 Tem 2019

  • CVE-2019-13643
    24İzleyin

    Stored XSS in EspoCRM before 5.6.4 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target

    OrtaCVSS 6,1İstismar yokEPSS %1

    espocrm · espocrm17 Tem 2019

  • CVE-2019-14349
    24İzleyin

    EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for s

    OrtaCVSS 6,1İstismar yokEPSS %1

    espocrm · espocrm28 Tem 2019

  • CVE-2019-14350
    24İzleyin

    EspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base.

    OrtaCVSS 6,1İstismar yokEPSS %1

    espocrm · espocrm28 Tem 2019

  • CVE-2022-38845
    24İzleyin

    Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending craf

    OrtaCVSS 6,1İstismar yokEPSS %1

    espocrm · espocrm16 Eyl 2022

  • CVE-2024-24818
    23İzleyin

    EspoCRM weakness in "Forgot password"

    OrtaCVSS 5,9İstismar yokEPSS %1

    espocrm · espocrm20 Mar 2024

  • CVE-2022-38846
    23İzleyin

    EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP).

    OrtaCVSS 5,9İstismar yokEPSS %0

    espocrm · espocrm16 Eyl 2022

  • CVE-2014-7986
    21İzleyin

    install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the installProcess paramete

    OrtaCVSS 5,0İstismar yokEPSS %3

    espocrm · espocrm31 Eki 2014

  • CVE-2019-14546
    21İzleyin

    An issue was discovered in EspoCRM before 5.6.9.

    OrtaCVSS 5,4İstismar yokEPSS %1

    espocrm · espocrm5 Ağu 2019