Espocrm

Espocrm

49 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 08.10.2026 14:10:32
  • Zuletzt bearbeitet 08.10.2026 18:17:15

EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\Service that allows users with Email Account scope access to retrieve other users' IMAP passwords. Attackers who know a victim's Email Account record ...

  • EPSS -
  • Veröffentlicht 08.10.2026 14:10:32
  • Zuletzt bearbeitet 08.10.2026 15:17:35

EspoCRM before 10.0.6 contains an authentication bypass vulnerability that accepts a login stopped at the second factor on routes not requiring authentication. Attackers knowing a 2FA-enabled user's username and password can skip the second factor to...

  • EPSS -
  • Veröffentlicht 08.10.2026 14:10:31
  • Zuletzt bearbeitet 08.10.2026 18:17:14

EspoCRM before 10.0.6 contains a stored HTML injection vulnerability that allows unauthenticated attackers to inject HTML by submitting crafted Lead Capture public form data. The request body is stored in LeadCaptureLogRecord.data and rendered unesca...

  • EPSS 0.32%
  • Veröffentlicht 16.09.2026 01:57:46
  • Zuletzt bearbeitet 08.10.2026 16:18:00

EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and campaign URLs instead of a cryptographically secure generator. Remote unauthenticated attackers can guess these roughly 31-bit tokens ...

  • EPSS 0.18%
  • Veröffentlicht 14.09.2026 12:48:29
  • Zuletzt bearbeitet 23.09.2026 17:17:47

EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints that allows authenticated users to read restricted email addresses. Attackers can recover hidden attendee emails by exploiting inco...

  • EPSS 0.34%
  • Veröffentlicht 10.09.2026 13:05:43
  • Zuletzt bearbeitet 15.09.2026 15:17:26

EspoCRM before 10.0.4 is vulnerable to server-side request forgery. HostCheck::ipAddressIsNotInternal(), which validates outbound URLs to block requests to internal/private IP addresses, strips ::ffff: (IPv4-mapped IPv6) prefixes but does not recogni...

  • EPSS 0.35%
  • Veröffentlicht 28.05.2026 16:25:03
  • Zuletzt bearbeitet 28.05.2026 20:16:23

EspoCRM is an open source customer relationship management application. Prior to 9.3.5, the POST /api/v1/EmailTemplate/:id/prepare endpoint accepts an emailAddress parameter and resolves the owning entity (Contact, Lead, Account, or User) without per...

  • EPSS 0.29%
  • Veröffentlicht 28.05.2026 16:24:19
  • Zuletzt bearbeitet 28.05.2026 20:16:23

EspoCRM is an open source customer relationship management application. Prior to 9.3.5, a business logic flaw (Broken Access Control) in EspoCRM 9.3.3 allows low-privileged users to pin arbitrary notes without having the required edit permissions for...

  • EPSS 0.21%
  • Veröffentlicht 19.05.2026 18:14:36
  • Zuletzt bearbeitet 24.07.2026 09:10:00

EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated users to upload SVG attachments through normal attachment-capable fields and later serve those SVG files as top-level inline document...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 22.04.2026 20:05:23
  • Zuletzt bearbeitet 27.04.2026 15:08:59

EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template management endpoints accept attacker-controlled `name` and `scope` values and pass them into template path construction without normali...