CVE-2026-41141
- EPSS 0.35%
- Veröffentlicht 28.05.2026 16:25:03
- Zuletzt bearbeitet 28.05.2026 20:16:23
EspoCRM is an open source customer relationship management application. Prior to 9.3.5, the POST /api/v1/EmailTemplate/:id/prepare endpoint accepts an emailAddress parameter and resolves the owning entity (Contact, Lead, Account, or User) without per...
CVE-2026-41160
- EPSS 0.29%
- Veröffentlicht 28.05.2026 16:24:19
- Zuletzt bearbeitet 28.05.2026 20:16:23
EspoCRM is an open source customer relationship management application. Prior to 9.3.5, a business logic flaw (Broken Access Control) in EspoCRM 9.3.3 allows low-privileged users to pin arbitrary notes without having the required edit permissions for...
CVE-2026-33741
- EPSS 0.21%
- Veröffentlicht 19.05.2026 18:14:36
- Zuletzt bearbeitet 20.05.2026 14:16:42
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated users to upload SVG attachments through normal attachment-capable fields and later serve those SVG files as top-level inline document...
CVE-2026-33733
- EPSS 0.45%
- Veröffentlicht 22.04.2026 20:05:23
- Zuletzt bearbeitet 27.04.2026 15:08:59
EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template management endpoints accept attacker-controlled `name` and `scope` values and pass them into template path construction without normali...
CVE-2026-33656
- EPSS 0.5%
- Veröffentlicht 22.04.2026 20:01:24
- Zuletzt bearbeitet 27.04.2026 17:04:54
EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing updating attachment's sourceId thus allowing an authenticated admin to overwrite the `sourceId` field...
CVE-2026-33740
- EPSS 0.21%
- Veröffentlicht 13.04.2026 20:37:28
- Zuletzt bearbeitet 22.04.2026 00:04:34
EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Email/importEml endpoint contains an Insecure Direct Object Reference (IDOR) vulnerability where the attacker-supplied fileId parame...
CVE-2026-33659
- EPSS 0.33%
- Veröffentlicht 13.04.2026 20:32:07
- Zuletzt bearbeitet 22.04.2026 00:07:49
EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Attachment/fromImageUrl endpoint is vulnerable to Server-Side Request Forgery (SSRF) via a DNS rebinding (TOCTOU) condition. Host va...
CVE-2026-33657
- EPSS 0.18%
- Veröffentlicht 13.04.2026 19:41:47
- Zuletzt bearbeitet 22.04.2026 00:10:21
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML injection vulnerability that allows any authenticated user with standard (non-administrative) privileges to inject arbitrary HTML into...
CVE-2026-33534
- EPSS 1.98%
- Veröffentlicht 13.04.2026 19:20:04
- Zuletzt bearbeitet 22.04.2026 00:12:27
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have an authenticated Server-Side Request Forgery (SSRF) vulnerability that allows bypassing the internal-host validation logic by using alternative IPv4...
CVE-2020-37094
- EPSS 0.55%
- Veröffentlicht 03.02.2026 22:16:25
- Zuletzt bearbeitet 03.03.2026 14:59:29
EspoCRM 5.8.5 contains an authentication vulnerability that allows attackers to access other user accounts by manipulating authorization headers. Attackers can decode and modify Basic Authorization and Espo-Authorization tokens to gain unauthorized a...