| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-67587 | WordPress WP Gravity Forms FreshDesk Plugin plugin <= 1.3.5 - Open Redirection vulnerability | CRM Perks | WP Gravity Forms FreshDesk Plugin | Medium | 4.7 | 2025-12-09 14:14:17 | Deep Dive |
| CVE-2025-67468 | WordPress Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin <= 1.4.6 - Broken Access Control vulnerability | CRM Perks | Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms | Medium | 4.3 | 2025-12-09 14:13:56 | Deep Dive |
| CVE-2025-14189 | Chanjet CRM jxf_dump_table_demo.php sql injection | Chanjet | CRM | High | 7.3 | 2025-12-07 11:32:05 | Deep Dive |
| CVE-2025-13312 | CRM Memberships <= 2.5 - Missing Authorization to Unauthenticated 'ntzcrm_add_new_tag' AJAX Action | dripadmin | CRM Memberships | Medium | 5.3 | 2025-12-05 04:29:13 | Deep Dive |
| CVE-2025-13313 | CRM Memberships <= 2.6 - Missing Authorization to Privilege Escalation via Unauthenticated Password Reset in 'ntzcrm_changepassword' AJAX Endpoint | dripadmin | CRM Memberships | Critical | 9.8 | 2025-12-05 04:29:12 | Deep Dive |
| CVE-2025-66313 | ChurchCRM vulnerable to a time-based blind SQL injection via the 1FieldSec parameter | ChurchCRM | CRM | - | - | 2025-12-01 22:13:20 | Deep Dive |
| CVE-2025-13788 | Chanjet CRM upgradeattribute.php sql injection | Chanjet | CRM | High | 7.3 | 2025-11-30 12:32:06 | Deep Dive |
| CVE-2025-11461 | Frappe CRM 1.53.1 — Multiple SQL Injections in Dashboard Controller | Frappe | Frappe CRM | - | - | 2025-11-26 17:45:05 | Deep Dive |
| CVE-2025-12935 | FluentCRM - Marketing Automation For WordPress <= 2.9.84 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'fluentcrm_content' Shortcode | techjewel | FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution | Medium | 6.4 | 2025-11-21 12:28:08 | Deep Dive |
| CVE-2025-12750 | Groundhogg <= 4.2.6.1 - Authenticated (Admin+) SQL Injection | trainingbusinesspros | Groundhogg — CRM, Newsletters, and Marketing Automation | Medium | 4.9 | 2025-11-21 09:27:03 | Deep Dive |
| CVE-2025-41106 | Multiple vulnerabilities in Fairsketch's RISE CRM Framework | Fairsketch | RISE CRM Framework | 中危 | - | 2025-11-11 12:21:07 | Deep Dive |
| CVE-2025-41105 | Multiple vulnerabilities in Fairsketch's RISE CRM Framework | Fairsketch | RISE CRM Framework | 中危 | - | 2025-11-11 12:19:06 | Deep Dive |
| CVE-2025-41104 | Multiple vulnerabilities in Fairsketch's RISE CRM Framework | Fairsketch | RISE CRM Framework | 中危 | - | 2025-11-11 12:17:41 | Deep Dive |
| CVE-2025-41103 | Multiple vulnerabilities in Fairsketch's RISE CRM Framework | Fairsketch | RISE CRM Framework | 中危 | - | 2025-11-11 12:16:39 | Deep Dive |
| CVE-2025-41102 | Multiple vulnerabilities in Fairsketch's RISE CRM Framework | Fairsketch | RISE CRM Framework | 中危 | - | 2025-11-11 11:57:40 | Deep Dive |
| CVE-2025-41101 | Multiple vulnerabilities in Fairsketch's RISE CRM Framework | Fairsketch | RISE CRM Framework | 中危 | - | 2025-11-11 11:50:20 | Deep Dive |
| CVE-2025-58636 | WordPress WP Gravity Forms Keap/Infusionsoft Plugin <= 1.2.3 - Deserialization of untrusted data Vulnerability | CRM Perks | WP Gravity Forms Keap/Infusionsoft | 中危 | - | 2025-11-06 15:54:27 | Deep Dive |
| CVE-2025-12469 | FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending | amans2k | FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce | Medium | 4.3 | 2025-11-05 09:27:40 | Deep Dive |
| CVE-2025-12468 | FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Unauthenticated Sensitive Information Exposure | amans2k | FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce | Medium | 5.3 | 2025-11-05 09:27:39 | Deep Dive |
| CVE-2025-62981 | WordPress WP Gravity Forms Zoho CRM and Bigin plugin <= 1.2.8 - Open Redirection vulnerability | CRM Perks | WP Gravity Forms Zoho CRM and Bigin | Medium | 4.7 | 2025-10-27 01:34:20 | Deep Dive |