CVE-2026-33740
- EPSS 0.02%
- Veröffentlicht 13.04.2026 20:37:28
- Zuletzt bearbeitet 17.04.2026 15:26:13
EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Email/importEml endpoint contains an Insecure Direct Object Reference (IDOR) vulnerability where the attacker-supplied fileId parame...
CVE-2026-33659
- EPSS 0.04%
- Veröffentlicht 13.04.2026 20:32:07
- Zuletzt bearbeitet 17.04.2026 15:26:13
EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Attachment/fromImageUrl endpoint is vulnerable to Server-Side Request Forgery (SSRF) via a DNS rebinding (TOCTOU) condition. Host va...
CVE-2026-33657
- EPSS 0.03%
- Veröffentlicht 13.04.2026 19:41:47
- Zuletzt bearbeitet 17.04.2026 15:38:09
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML injection vulnerability that allows any authenticated user with standard (non-administrative) privileges to inject arbitrary HTML into...
CVE-2026-33534
- EPSS 0.03%
- Veröffentlicht 13.04.2026 19:20:04
- Zuletzt bearbeitet 17.04.2026 15:38:09
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have an authenticated Server-Side Request Forgery (SSRF) vulnerability that allows bypassing the internal-host validation logic by using alternative IPv4...
CVE-2020-37094
- EPSS 0.41%
- Veröffentlicht 03.02.2026 22:16:25
- Zuletzt bearbeitet 03.03.2026 14:59:29
EspoCRM 5.8.5 contains an authentication vulnerability that allows attackers to access other user accounts by manipulating authorization headers. Attackers can decode and modify Basic Authorization and Espo-Authorization tokens to gain unauthorized a...
CVE-2025-59428
- EPSS 0.02%
- Veröffentlicht 14.10.2025 14:38:20
- Zuletzt bearbeitet 20.10.2025 18:12:29
EspoCRM is an open source customer relationship management application. In versions before 9.1.9, a vulnerability allows arbitrary user creation, including administrative accounts, through a combination of stored SVG injection and lack of CSRF protec...
CVE-2025-52892
- EPSS 0.04%
- Veröffentlicht 05.08.2025 00:17:16
- Zuletzt bearbeitet 11.09.2025 17:14:04
EspoCRM is a web application with a frontend designed as a single-page application and a REST API backend written in PHP. In versions 9.1.6 and below, if a user loads Espo in the browser with double slashes (e.g https://domain//#Admin) and the webser...
CVE-2025-52575
- EPSS 0.36%
- Veröffentlicht 21.07.2025 17:48:11
- Zuletzt bearbeitet 05.08.2025 17:53:32
EspoCRM is an Open Source CRM (Customer Relationship Management) software. EspoCRM versions 9.1.6 and earlier are vulnerable to blind LDAP Injection when LDAP authentication is enabled. A remote, unauthenticated attacker can manipulate LDAP queries b...
CVE-2025-32390
- EPSS 0.32%
- Veröffentlicht 12.05.2025 10:30:52
- Zuletzt bearbeitet 17.06.2025 19:41:34
EspoCRM is a free, open-source customer relationship management platform. Prior to version 9.0.8, HTML Injection in Knowledge Base (KB) articles leads to complete page defacement imitating the login page. Authenticated users with the read knowledge a...
CVE-2025-32789
- EPSS 0.18%
- Veröffentlicht 16.04.2025 21:45:21
- Zuletzt bearbeitet 18.06.2025 13:08:03
EspoCRM is an Open Source Customer Relationship Management software. Prior to version 9.0.7, users can be sorted by their password hash. This flaw allows an attacker to make assumptions about the hash values of other users stored in the password colu...