Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

crm — Vulnerabilities & Security Advisories 87

All 87 CVE vulnerabilities found in crm, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations associated with the CRM product category and its various software vendors. It aggregates security vulnerability data to provide a centralized view of the risk landscape for customer relationship management systems, focusing on weaknesses such as injection flaws, cross-site scripting, and insecure direct object references that commonly affect this domain. The collection covers publicly disclosed vulnerabilities from January 2020 through the current date, ensuring that both legacy issues and recent findings are included in the analysis. Visitors can use this resource to track vendor security advisories over time, understand the prevalence and impact of specific weakness classes within the CRM ecosystem, and look up a particular product’s historical vulnerability record to assess its long-term security posture. By examining trends and patterns across multiple vendors, users can identify systemic issues that may affect the entire industry segment rather than isolated incidents. The data is organized to facilitate comparative analysis, allowing security teams to prioritize remediation efforts based on severity and exposure. This approach supports informed decision-making for IT administrators and security analysts responsible for maintaining the integrity of CRM deployments. The page does not endorse any specific vendor but aims to provide neutral, factual information to enhance transparency and improve overall security hygiene in the customer relationship management sector.

Vendor: oroinc

CVE IDTitleCVSSSeverityPublished
CVE-2025-68109 ChurchCRM vulnerable to RCE with database restore functionality CWE-78 9.1 Critical2025-12-17
CVE-2025-67877 ChurchCRM SQL Injection Vulnerability CWE-89 8.8AIHighAI2025-12-17
CVE-2025-67876 ChurchCRM has Stored XSS in Group Role Name Leading to Admin Session Hijacking CWE-79 5.4AIMediumAI2025-12-17
CVE-2025-67875 ChurchCRM has stored XSS via Person Property Assignment Leading to Admin Session Hijacking CWE-79 7.6AIHighAI2025-12-17
CVE-2025-66397 ChurchCRM's Kiosk Manager Functions are vulnerable to Broken Access Control CWE-284 8.3 High2025-12-17
CVE-2025-66396 ChurchCRM has SQL Injection in User Editor via `type` Parameter Key CWE-89 7.2 High2025-12-17
CVE-2025-66395 SQL Injection in Event List via `WhichType` Parameter CWE-89 8.8 High2025-12-17
CVE-2025-62521 ChurchCRM has unauthenticated RCE in its Install Wizard CWE-94 10.0 Critical2025-12-17
CVE-2025-67751 ChurchCRM has SQL Injection in Event Editor via `EN_tyid` Parameter caused by an Incomplete Fix CWE-89 7.2 High2025-12-16
CVE-2025-67874 ChurchCRM has plaintext password return in response CWE-204 8.1AIHighAI2025-12-16
CVE-2025-14189 Chanjet CRM jxf_dump_table_demo.php sql injection CWE-89 7.3 High2025-12-07
CVE-2025-66313 ChurchCRM vulnerable to a time-based blind SQL injection via the 1FieldSec parameter CWE-89 7.7AIHighAI2025-12-01
CVE-2025-13788 Chanjet CRM upgradeattribute.php sql injection CWE-89 7.3 High2025-11-30
CVE-2025-7915 Chanjet CRM Login Page mailinactive.php sql injection CWE-89 7.3 High2025-07-21
CVE-2025-7801 BossSoft CRM HNDCBas_customPrmSearchDtl.jsp sql injection CWE-89 7.3 High2025-07-18
CVE-2025-6132 Chanjet CRM departmentsetting.php sql injection CWE-89 7.3 High2025-06-16
CVE-2025-5152 Chanjet CRM newActivityedit.php sql injection CWE-89 6.3 Medium2025-05-25
CVE-2025-1618 vTiger CRM index.php cross site scripting CWE-79 4.3 Medium2025-02-24
CVE-2024-8867 Perfex CRM Parameter Clients.php cross site scripting CWE-79 3.5 Low2024-09-15
CVE-2024-39304 ChurchCRM SQL Injection Vulnerability CWE-89 8.8 High2024-07-26
CVE-2023-32063 OroCRMCallBundle has incorrect call view page visibility CWE-284 5.0 Medium2023-11-28
CVE-2023-32062 OroCalendarBundle has incorrect system calendar events visibility CWE-284 5.0 Medium2023-11-27
CVE-2023-5020 07FLY CRM Administrator Login Page sql injection CWE-89 7.3 High2023-09-17
CVE-2023-3505 Onest CRM Project List 2 cross site scripting CWE-79 3.5 Low2023-07-04
CVE-2023-3058 07FLY CRM User Profile cross site scripting CWE-79 3.5 Low2023-06-02
CVE-2023-27897 Code Injection vulnerability in SAP CRM CWE-94 6.0 Medium2023-04-11
CVE-2021-39198 The disqualify lead action may be executed without CSRF token check CWE-352 4.2 Medium2021-11-19

All 87 known CVE vulnerabilities affecting crm with full Chinese analysis, references, and POCs where available.