Espocrm

Espocrm

49 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.5%
  • Veröffentlicht 22.04.2026 20:01:24
  • Zuletzt bearbeitet 27.04.2026 17:04:54

EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing updating attachment's sourceId thus allowing an authenticated admin to overwrite the `sourceId` field...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 13.04.2026 20:37:28
  • Zuletzt bearbeitet 22.04.2026 00:04:34

EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Email/importEml endpoint contains an Insecure Direct Object Reference (IDOR) vulnerability where the attacker-supplied fileId parame...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 13.04.2026 20:32:07
  • Zuletzt bearbeitet 22.04.2026 00:07:49

EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Attachment/fromImageUrl endpoint is vulnerable to Server-Side Request Forgery (SSRF) via a DNS rebinding (TOCTOU) condition. Host va...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 13.04.2026 19:41:47
  • Zuletzt bearbeitet 22.04.2026 00:10:21

EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML injection vulnerability that allows any authenticated user with standard (non-administrative) privileges to inject arbitrary HTML into...

Exploit
  • EPSS 1.98%
  • Veröffentlicht 13.04.2026 19:20:04
  • Zuletzt bearbeitet 22.04.2026 00:12:27

EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have an authenticated Server-Side Request Forgery (SSRF) vulnerability that allows bypassing the internal-host validation logic by using alternative IPv4...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 03.02.2026 22:16:25
  • Zuletzt bearbeitet 15.07.2026 02:17:03

EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to bypass two-factor authentication by exploiting token-to-password-hash mapping in application/Espo/Core/Utils/Authentication/Espo....

Exploit
  • EPSS 0.13%
  • Veröffentlicht 14.10.2025 14:38:20
  • Zuletzt bearbeitet 20.10.2025 18:12:29

EspoCRM is an open source customer relationship management application. In versions before 9.1.9, a vulnerability allows arbitrary user creation, including administrative accounts, through a combination of stored SVG injection and lack of CSRF protec...

  • EPSS 0.25%
  • Veröffentlicht 05.08.2025 00:17:16
  • Zuletzt bearbeitet 11.09.2025 17:14:04

EspoCRM is a web application with a frontend designed as a single-page application and a REST API backend written in PHP. In versions 9.1.6 and below, if a user loads Espo in the browser with double slashes (e.g https://domain//#Admin) and the webser...

Exploit
  • EPSS 0.71%
  • Veröffentlicht 21.07.2025 17:48:11
  • Zuletzt bearbeitet 05.08.2025 17:53:32

EspoCRM is an Open Source CRM (Customer Relationship Management) software. EspoCRM versions 9.1.6 and earlier are vulnerable to blind LDAP Injection when LDAP authentication is enabled. A remote, unauthenticated attacker can manipulate LDAP queries b...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 12.05.2025 10:30:52
  • Zuletzt bearbeitet 17.06.2025 19:41:34

EspoCRM is a free, open-source customer relationship management platform. Prior to version 9.0.8, HTML Injection in Knowledge Base (KB) articles leads to complete page defacement imitating the login page. Authenticated users with the read knowledge a...