Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

crm — Vulnerabilities & Security Advisories 87

All 87 CVE vulnerabilities found in crm, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations associated with the CRM product category and its various software vendors. It aggregates security vulnerability data to provide a centralized view of the risk landscape for customer relationship management systems, focusing on weaknesses such as injection flaws, cross-site scripting, and insecure direct object references that commonly affect this domain. The collection covers publicly disclosed vulnerabilities from January 2020 through the current date, ensuring that both legacy issues and recent findings are included in the analysis. Visitors can use this resource to track vendor security advisories over time, understand the prevalence and impact of specific weakness classes within the CRM ecosystem, and look up a particular product’s historical vulnerability record to assess its long-term security posture. By examining trends and patterns across multiple vendors, users can identify systemic issues that may affect the entire industry segment rather than isolated incidents. The data is organized to facilitate comparative analysis, allowing security teams to prioritize remediation efforts based on severity and exposure. This approach supports informed decision-making for IT administrators and security analysts responsible for maintaining the integrity of CRM deployments. The page does not endorse any specific vendor but aims to provide neutral, factual information to enhance transparency and improve overall security hygiene in the customer relationship management sector.

Vendor: oroinc

CVE ID Title CVSS Severity Published
CVE-2025-68109 ChurchCRM vulnerable to RCE with database restore functionality CWE-78 9.1 Critical 2025-12-17
CVE-2025-67877 ChurchCRM SQL Injection Vulnerability CWE-89 8.8AI High AI 2025-12-17
CVE-2025-67876 ChurchCRM has Stored XSS in Group Role Name Leading to Admin Session Hijacking CWE-79 5.4AI Medium AI 2025-12-17
CVE-2025-67875 ChurchCRM has stored XSS via Person Property Assignment Leading to Admin Session Hijacking CWE-79 7.6AI High AI 2025-12-17
CVE-2025-66397 ChurchCRM's Kiosk Manager Functions are vulnerable to Broken Access Control CWE-284 8.3 High 2025-12-17
CVE-2025-66396 ChurchCRM has SQL Injection in User Editor via `type` Parameter Key CWE-89 7.2 High 2025-12-17
CVE-2025-66395 SQL Injection in Event List via `WhichType` Parameter CWE-89 8.8 High 2025-12-17
CVE-2025-62521 ChurchCRM has unauthenticated RCE in its Install Wizard CWE-94 10.0 Critical 2025-12-17
CVE-2025-67751 ChurchCRM has SQL Injection in Event Editor via `EN_tyid` Parameter caused by an Incomplete Fix CWE-89 7.2 High 2025-12-16
CVE-2025-67874 ChurchCRM has plaintext password return in response CWE-204 8.1AI High AI 2025-12-16
CVE-2025-14189 Chanjet CRM jxf_dump_table_demo.php sql injection CWE-89 7.3 High 2025-12-07
CVE-2025-66313 ChurchCRM vulnerable to a time-based blind SQL injection via the 1FieldSec parameter CWE-89 7.7AI High AI 2025-12-01
CVE-2025-13788 Chanjet CRM upgradeattribute.php sql injection CWE-89 7.3 High 2025-11-30
CVE-2025-7915 Chanjet CRM Login Page mailinactive.php sql injection CWE-89 7.3 High 2025-07-21
CVE-2025-7801 BossSoft CRM HNDCBas_customPrmSearchDtl.jsp sql injection CWE-89 7.3 High 2025-07-18
CVE-2025-6132 Chanjet CRM departmentsetting.php sql injection CWE-89 7.3 High 2025-06-16
CVE-2025-5152 Chanjet CRM newActivityedit.php sql injection CWE-89 6.3 Medium 2025-05-25
CVE-2025-1618 vTiger CRM index.php cross site scripting CWE-79 4.3 Medium 2025-02-24
CVE-2024-8867 Perfex CRM Parameter Clients.php cross site scripting CWE-79 3.5 Low 2024-09-15
CVE-2024-39304 ChurchCRM SQL Injection Vulnerability CWE-89 8.8 High 2024-07-26
CVE-2023-32063 OroCRMCallBundle has incorrect call view page visibility CWE-284 5.0 Medium 2023-11-28
CVE-2023-32062 OroCalendarBundle has incorrect system calendar events visibility CWE-284 5.0 Medium 2023-11-27
CVE-2023-5020 07FLY CRM Administrator Login Page sql injection CWE-89 7.3 High 2023-09-17
CVE-2023-3505 Onest CRM Project List 2 cross site scripting CWE-79 3.5 Low 2023-07-04
CVE-2023-3058 07FLY CRM User Profile cross site scripting CWE-79 3.5 Low 2023-06-02
CVE-2023-27897 Code Injection vulnerability in SAP CRM CWE-94 6.0 Medium 2023-04-11
CVE-2021-39198 The disqualify lead action may be executed without CSRF token check CWE-352 4.2 Medium 2021-11-19

All 87 known CVE vulnerabilities affecting crm with full Chinese analysis, references, and POCs where available.