Software
espocrm
Aggregate across all detected versions
Total Hosts
0
distinct hosts
Versions Seen
0
Countries
0
Known CVEs
41
known CVEs
Top Countries
No geolocated hosts.
Top ASNs
No attributed hosts.
CVE Matches
| CVE | CVSS | Severity | Summary |
|---|---|---|---|
| CVE-2014-7985 | 10.0 | HIGH | Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action... |
| CVE-2020-37094 | 9.8 | N/A | EspoCRM 5.8.5 contains an authentication vulnerability that allows attackers to access other user accounts by manipulating authorization headers. Attackers can... |
| CVE-2026-33656 | 9.1 | N/A | EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing updating at... |
| CVE-2019-14351 | 8.8 | N/A | EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user password hash by 1 symbol at a time usi... |
| CVE-2022-38843 | 8.8 | N/A | EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server. Attacker may execu... |
| CVE-2025-32390 | 8.5 | N/A | EspoCRM is a free, open-source customer relationship management platform. Prior to version 9.0.8, HTML Injection in Knowledge Base (KB) articles leads to comple... |
| CVE-2020-37094 | 8.1 | N/A | EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to bypass two-factor authentication by exp... |
| CVE-2022-38844 | 8.0 | N/A | CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloads capable of execut... |
| CVE-2026-33733 | 7.2 | N/A | EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template management endpoints accept attacker-controll... |
| CVE-2025-52575 | 6.5 | N/A | EspoCRM is an Open Source CRM (Customer Relationship Management) software. EspoCRM versions 9.1.6 and earlier are vulnerable to blind LDAP Injection when LDAP a... |
| CVE-2021-3539 | 6.3 | N/A | EspoCRM 6.1.6 and prior suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was f... |
| CVE-2019-13643 | 6.1 | N/A | Stored XSS in EspoCRM before 5.6.4 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target pages. The attack be... |
| CVE-2019-14329 | 6.1 | N/A | An issue was discovered in EspoCRM before 5.6.6. There is stored XSS due to lack of filtration of user-supplied data in Create Task. A malicious attacker can mo... |
| CVE-2019-14330 | 6.1 | N/A | An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create Case. A malicious attacker can modi... |
| CVE-2019-14331 | 6.1 | N/A | An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create User. A malicious attacker can modi... |
| CVE-2019-14349 | 6.1 | N/A | EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for storing documents in... |
| CVE-2019-14350 | 6.1 | N/A | EspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base. A malicious attacker can inject JavaScript code... |
| CVE-2022-38845 | 6.1 | N/A | Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending crafted csv file contain... |
| CVE-2022-38846 | 5.9 | N/A | EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attacker may capt... |
| CVE-2024-24818 | 5.9 | N/A | EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "Password Change" page and redirect victim... |
| CVE-2018-17301 | 5.4 | N/A | Reflected XSS exists in client/res/templates/global-search/name-field.tpl in EspoCRM 5.3.6 via /#Account in the search panel. |
| CVE-2018-17302 | 5.4 | N/A | Stored XSS exists in views/fields/wysiwyg.js in EspoCRM 5.3.6 via a /#Email/view saved draft message. |
| CVE-2019-14546 | 5.4 | N/A | An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending an email when a malicious payload was i... |
| CVE-2019-14547 | 5.4 | N/A | An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin with malicious JavaScript in the filename.... |
| CVE-2019-14548 | 5.4 | N/A | An issue was discovered in EspoCRM before 5.6.9. Stored XSS in the body of an Article was executed when a victim opens articles received through mail. This Arti... |
| CVE-2019-14549 | 5.4 | N/A | An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed inside the title and breadcrumb of a newly formed entity available to all the users. A... |
| CVE-2019-14550 | 5.4 | N/A | An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a victim clicks on the Edit Dashboard feature present on the Homepage. An attacker... |
| CVE-2025-59428 | 5.4 | N/A | EspoCRM is an open source customer relationship management application. In versions before 9.1.9, a vulnerability allows arbitrary user creation, including admi... |
| CVE-2026-33740 | 5.4 | N/A | EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Email/importEml endpoint contains an Insec... |
| CVE-2023-46736 | 5.3 | N/A | EspoCRM is an Open Source CRM (Customer Relationship Management) software. In affected versions there is Server-Side Request Forgery (SSRF) vulnerability via th... |
| CVE-2025-32385 | 5.3 | N/A | EspoCRM is an Open Source Customer Relationship Management software. Prior to 9.0.5, Iframe dashlet allows user to display iframes with arbitrary URLs. As the s... |
| CVE-2014-7986 | 5.0 | MEDIUM | install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the installProcess parameter. |
| CVE-2023-5965 | 4.7 | N/A | An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the update form, which could lead to arbit... |
| CVE-2023-5966 | 4.7 | N/A | An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, which could... |
| CVE-2026-33657 | 4.6 | N/A | EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML injection vulnerability that allows any auth... |
| CVE-2025-52892 | 4.5 | N/A | EspoCRM is a web application with a frontend designed as a single-page application and a REST API backend written in PHP. In versions 9.1.6 and below, if a user... |
| CVE-2014-7987 | 4.3 | MEDIUM | Cross-site scripting (XSS) vulnerability in EspoCRM before 2.6.0 allows remote attackers to inject arbitrary web script or HTML via the desc parameter in an err... |
| CVE-2026-33534 | 4.3 | N/A | EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have an authenticated Server-Side Request Forgery (SSRF) vulner... |
| CVE-2014-8330 | 3.5 | LOW | Cross-site scripting (XSS) vulnerability in EspoCRM allows remote authenticated users to inject arbitrary web script or HTML via the Name field in a new account... |
| CVE-2026-33659 | 3.5 | N/A | EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Attachment/fromImageUrl endpoint is vulner... |