Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

EspoCRM — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in EspoCRM, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities associated with EspoCRM, an open-source customer relationship management application, categorized under general software weakness types. It aggregates historical data regarding known flaws, including but not limited to SQL injection, cross-site scripting, and insecure direct object references, covering incident reports from early development releases through recent major versions. Users can utilize this resource to track vendor advisories issued by the EspoCRM development team, understand the prevalence and impact of specific weakness classes within the application architecture, and look up the comprehensive vulnerability history of the product to assess security posture over time. The information is organized to facilitate efficient analysis for security researchers, system administrators, and compliance auditors who need to evaluate risk exposure and prioritize remediation efforts based on verified historical records rather than speculative threats. By centralizing these details, the page aims to reduce the time required to identify relevant security issues and support informed decision-making regarding updates and patch management strategies for deployed EspoCRM instances. This approach ensures that stakeholders have access to a consistent and structured view of past security incidents, enabling them to correlate current system configurations with known problematic patterns and implement appropriate mitigations effectively.

Vendor: EspoCRM

CVE ID Title CVSS Severity Published
CVE-2026-41141 EspoCRM: IDOR in EmailTemplate Prepare Endpoint Leaks Entity Data via Email Address Lookup CWE-639 6.5 Medium 2026-05-28
CVE-2026-41160 EspoCRM: Broken Access Control / IDOR in Note Pinning API allows unauthorized modification of notes CWE-284 4.3 Medium 2026-05-28
CVE-2026-33741 EspoCRM: Stored XSS via SVG attachment loading same-origin JavaScript CWE-79 6.8 Medium 2026-05-19
CVE-2026-33733 EspoCRM has Admin TemplateManager path traversal that allows arbitrary file read write and delete CWE-23 7.2 High 2026-04-22
CVE-2026-33656 EspoCRM vulnerable to authenticated RCE via Formula with path traversal in attachment `sourceId`, exploitable by admin user CWE-22 9.1 Critical 2026-04-22
CVE-2026-33740 EspoCRM: Email importEml can import and delete another user's attachment by raw fileId CWE-639 5.4 Medium 2026-04-13
CVE-2026-33659 EspoCRM: SSRF via DNS Rebinding in Attachment fromImageUrl Endpoint Allows Internal Network Access CWE-918 3.5 Low 2026-04-13
CVE-2026-33657 EspoCRM: Stored HTML injection in email notifications about stream notes via unescaped post field CWE-80 4.6 Medium 2026-04-13
CVE-2026-33534 EspoCRM has authenticated SSRF via internal-host validation bypass using alternative IPv4 notation CWE-918 4.3 Medium 2026-04-13
CVE-2020-37094 EspoCRM 5.7.0 < 5.9.0 - Two-Factor Authentication Bypass via Auth Token Reuse Between Accounts with Identical Passwords CWE-303 8.1 High 2026-02-03
CVE-2025-59428 EspoCRM allows arbitrary user creation via stored SVG injection and CSRF CWE-352 5.4 Medium 2025-10-14
CVE-2025-52892 EspoCRM is vulnerable to access denial through double slash in URI corrupting router cache CWE-444 4.5 Medium 2025-08-05
CVE-2025-52575 EspoCRM vulnerable to LDAP Injection through Improper Neutralization of Special Elements CWE-90 6.5 Medium 2025-07-21
CVE-2025-32390 EspoCRM vulnerable to HTML Injection into phishing, which may lead to account takeover CWE-74 4.6AI Medium AI 2025-05-12
CVE-2025-32789 EspoCRM Allows Potential Disclosure of Sensitive Information in the User Sorting Function CWE-200 3.1 Low 2025-04-16
CVE-2025-32385 EspoCRM allows unrestricted Embedding in Iframe dashlet CWE-1021 5.3 Medium 2025-04-15
CVE-2024-24818 EspoCRM weakness in "Forgot password" CWE-610 5.9 Medium 2024-02-29
CVE-2023-46736 Server-Side Request Forgery in espocrm CWE-918 5.3 Medium 2023-12-05
CVE-2023-5966 Unrestricted Upload of File with Dangerous Type in EspoCRM CWE-434 4.7 Medium 2023-11-30
CVE-2023-5965 Unrestricted Upload of File with Dangerous Type in EspoCRM CWE-434 4.7 Medium 2023-11-30
CVE-2021-3539 EspoCRM Avatar Persistent XSS CWE-79 6.3 Medium 2021-08-04

All 21 known CVE vulnerabilities affecting EspoCRM with full Chinese analysis, references, and POCs where available.