Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

crm — Vulnerabilities & Security Advisories 87

All 87 CVE vulnerabilities found in crm, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations associated with the CRM product category and its various software vendors. It aggregates security vulnerability data to provide a centralized view of the risk landscape for customer relationship management systems, focusing on weaknesses such as injection flaws, cross-site scripting, and insecure direct object references that commonly affect this domain. The collection covers publicly disclosed vulnerabilities from January 2020 through the current date, ensuring that both legacy issues and recent findings are included in the analysis. Visitors can use this resource to track vendor security advisories over time, understand the prevalence and impact of specific weakness classes within the CRM ecosystem, and look up a particular product’s historical vulnerability record to assess its long-term security posture. By examining trends and patterns across multiple vendors, users can identify systemic issues that may affect the entire industry segment rather than isolated incidents. The data is organized to facilitate comparative analysis, allowing security teams to prioritize remediation efforts based on severity and exposure. This approach supports informed decision-making for IT administrators and security analysts responsible for maintaining the integrity of CRM deployments. The page does not endorse any specific vendor but aims to provide neutral, factual information to enhance transparency and improve overall security hygiene in the customer relationship management sector.

Vendor: oroinc

CVE ID Title CVSS Severity Published
CVE-2026-39333 ChurchCRM has Reflected XSS in DateStart/DateEnd parameters in FindFundRaiser.php CWE-79 8.7 High 2026-04-07
CVE-2026-39332 ChurchCRM has Reflected Cross-Site Scripting (XSS) in GeoPage.php CWE-79 8.7 High 2026-04-07
CVE-2026-39331 ChurchCRM has an API Authorization Bypass Allows Authenticated User to Deactivate, Modify, and Spam Arbitrary Families CWE-639 8.1 High 2026-04-07
CVE-2026-39330 ChurchCRM has a Blind SQL injection in PropertyAssign.php CWE-89 8.8 High 2026-04-07
CVE-2026-39329 ChurchCRM has a Blind SQL injection in EventNames.php CWE-89 8.8 High 2026-04-07
CVE-2026-39328 ChurchCRM has Stored XSS in Social Profile Fields CWE-79 8.9 High 2026-04-07
CVE-2026-39327 ChurchCRM has a SQL injection in MemberRoleChange.php CWE-89 8.8 High 2026-04-07
CVE-2026-39326 ChurchCRM has a Blind SQL injection in PropertyTypeEditor.php CWE-89 8.8 High 2026-04-07
CVE-2026-39325 ChurchCRM has a Blind SQL injection in SettingsUser.php CWE-89 7.2 High 2026-04-07
CVE-2026-39318 ChurchCRM has a DDL SQL Injection in GroupPropsFormRowOps.php CWE-89 8.8 High 2026-04-07
CVE-2026-39335 ChurchCRM has Stored XSS via Unescaped data-* Attributes in Group/Family Controls CWE-79 6.1 Medium 2026-04-07
CVE-2026-35576 ChurchCRM has Stored Cross-Site Scripting (XSS) in Person Properties via PrintView.php CWE-79 8.7 High 2026-04-07
CVE-2026-35575 ChurchCRM has Stored XSS in Group Name CWE-79 8.0 High 2026-04-07
CVE-2026-35572 SSRF via Referer header in ChurchCRM allows server-side HTTP/HTTPS requests to arbitrary hosts CWE-918 7.1AI High AI 2026-04-07
CVE-2026-35573 ChurchCRM has a Path traversal leads to RCE CWE-22 9.1 Critical 2026-04-07
CVE-2026-35574 ChurchCRM has a Stored XSS in Person Profile - Add a Note CWE-79 7.3 High 2026-04-07
CVE-2026-35534 ChurchCRM has Stored XSS in PersonView.php via Facebook Field Attribute Injection CWE-79 7.6 High 2026-04-07
CVE-2026-32880 ChurchCRM is vulnerable to Stored XSS through JSON handling in SystemSettings.php CWE-79 6.4 Medium 2026-03-20
CVE-2026-26059 ChurchCRM has Stored Cross-Site Scripting (XSS) in GroupEditor.php CWE-79 5.4 - 2026-02-19
CVE-2026-24855 ChurchCRM has Stored Cross-Site Scripting (XSS) in Create Events in Church Calendar, Leading to Account Takeover CWE-79 5.4AI Medium AI 2026-01-30
CVE-2026-24854 Church CRM has SQL injection in PaddleNumEditor.php CWE-89 8.8 High 2026-01-30
CVE-2021-47779 Dolibarr ERP-CRM 14.0.2 - Stored Cross-Site Scripting (XSS) / Privilege Escalation CWE-79 5.4 Medium 2026-01-15
CVE-2025-68928 Frappe CRM vulnerable to authenticated XSS via website field CWE-79 5.4 Medium 2025-12-29
CVE-2025-68275 ChurchCRM vulnerable to Stored XSS - Group name > Person Listing CWE-79 5.4AI Medium AI 2025-12-17
CVE-2025-68401 ChurchCRM has Stored Cross-Site Scripting (XSS) vulnerability that leads to session theft and account takeover CWE-79 7.6AI High AI 2025-12-17
CVE-2025-68400 ChurchCRM vulnerable to time-based blind SQL Injection in ConfirmReportEmail.php CWE-89 8.8AI High AI 2025-12-17
CVE-2025-68399 ChurchCRM has Stored Cross-Site Scripting (XSS) In GroupEditor.php CWE-79 5.4AI Medium AI 2025-12-17
CVE-2025-68112 ChurchCRM has SQL injection in EditEventAttendees.php CWE-89 9.6 Critical 2025-12-17
CVE-2025-68111 ChurchCRM has SQL Injection in eGive Import Feature CWE-89 7.2 High 2025-12-17
CVE-2025-68110 ChurchCRM discloses database information on error message CWE-200 10.0 Critical 2025-12-17

All 87 known CVE vulnerabilities affecting crm with full Chinese analysis, references, and POCs where available.