CVE-2026-105833
- EPSS -
- Veröffentlicht 08.10.2026 14:10:32
- Zuletzt bearbeitet 08.10.2026 18:17:15
EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\Service that allows users with Email Account scope access to retrieve other users' IMAP passwords. Attackers who know a victim's Email Account record ...
CVE-2026-105832
- EPSS -
- Veröffentlicht 08.10.2026 14:10:32
- Zuletzt bearbeitet 08.10.2026 15:17:35
EspoCRM before 10.0.6 contains an authentication bypass vulnerability that accepts a login stopped at the second factor on routes not requiring authentication. Attackers knowing a 2FA-enabled user's username and password can skip the second factor to...
CVE-2026-105831
- EPSS -
- Veröffentlicht 08.10.2026 14:10:31
- Zuletzt bearbeitet 08.10.2026 18:17:14
EspoCRM before 10.0.6 contains a stored HTML injection vulnerability that allows unauthenticated attackers to inject HTML by submitting crafted Lead Capture public form data. The request body is stored in LeadCaptureLogRecord.data and rendered unesca...
CVE-2026-92298
- EPSS 0.32%
- Veröffentlicht 16.09.2026 01:57:46
- Zuletzt bearbeitet 08.10.2026 16:18:00
EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and campaign URLs instead of a cryptographically secure generator. Remote unauthenticated attackers can guess these roughly 31-bit tokens ...
CVE-2026-90934
- EPSS 0.18%
- Veröffentlicht 14.09.2026 12:48:29
- Zuletzt bearbeitet 23.09.2026 17:17:47
EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints that allows authenticated users to read restricted email addresses. Attackers can recover hidden attendee emails by exploiting inco...
CVE-2026-88896
- EPSS 0.34%
- Veröffentlicht 10.09.2026 13:05:43
- Zuletzt bearbeitet 15.09.2026 15:17:26
EspoCRM before 10.0.4 is vulnerable to server-side request forgery. HostCheck::ipAddressIsNotInternal(), which validates outbound URLs to block requests to internal/private IP addresses, strips ::ffff: (IPv4-mapped IPv6) prefixes but does not recogni...
CVE-2026-41141
- EPSS 0.35%
- Veröffentlicht 28.05.2026 16:25:03
- Zuletzt bearbeitet 28.05.2026 20:16:23
EspoCRM is an open source customer relationship management application. Prior to 9.3.5, the POST /api/v1/EmailTemplate/:id/prepare endpoint accepts an emailAddress parameter and resolves the owning entity (Contact, Lead, Account, or User) without per...
CVE-2026-41160
- EPSS 0.29%
- Veröffentlicht 28.05.2026 16:24:19
- Zuletzt bearbeitet 28.05.2026 20:16:23
EspoCRM is an open source customer relationship management application. Prior to 9.3.5, a business logic flaw (Broken Access Control) in EspoCRM 9.3.3 allows low-privileged users to pin arbitrary notes without having the required edit permissions for...
CVE-2026-33741
- EPSS 0.21%
- Veröffentlicht 19.05.2026 18:14:36
- Zuletzt bearbeitet 24.07.2026 09:10:00
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated users to upload SVG attachments through normal attachment-capable fields and later serve those SVG files as top-level inline document...
CVE-2026-33733
- EPSS 0.45%
- Veröffentlicht 22.04.2026 20:05:23
- Zuletzt bearbeitet 27.04.2026 15:08:59
EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template management endpoints accept attacker-controlled `name` and `scope` values and pass them into template path construction without normali...