Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

EspoCRM — Vulnerabilities & Security Advisories 27

Browse all 27 CVE security advisories affecting EspoCRM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

EspoCRM serves as a customer relationship management platform for sales, marketing, and service operations. Historically, it has faced vulnerabilities including remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation and access control flaws. The platform's 18 recorded CVEs highlight recurring issues in its API and file handling components. While no major public security incidents have been widely documented, the consistent pattern of vulnerabilities suggests a need for rigorous patch management and security hardening. Organizations implementing EspoCRM should prioritize regular updates and implement least privilege configurations to mitigate potential exploitation risks.

Found 27 results / 27 Clear Filters
Top products by EspoCRM: EspoCRM
CVE ID Title CVSS Severity Published
CVE-2026-105833 EspoCRM before 10.0.5 IDOR via PersonalAccount Service Exposes IMAP Passwords — espocrm CWE-522 7.7 High 2026-10-08
CVE-2026-105832 EspoCRM before 10.0.6 Two-Factor Authentication Bypass on Unauthenticated Routes — espocrm CWE-287 4.3 Medium 2026-10-08
CVE-2026-105831 EspoCRM before 10.0.6 Unauthenticated Stored HTML Injection via Lead Capture Form — espocrm CWE-79 4.3 Medium 2026-10-08
CVE-2026-92298 EspoCRM through 10.0.8 Weak Token Generation via rand() — EspoCRM CWE-338 4.8 Medium 2026-09-16
CVE-2026-90934 EspoCRM before 10.0.4 Field-level Security Bypass via Attendees — espocrm CWE-863 4.3 Medium 2026-09-14
CVE-2026-88896 EspoCRM before 10.0.4 SSRF via IPv6 Transition Address Bypass — espocrm CWE-918 5.3 Medium 2026-09-10
CVE-2026-41141 EspoCRM: IDOR in EmailTemplate Prepare Endpoint Leaks Entity Data via Email Address Lookup — espocrm CWE-639 6.5 Medium 2026-05-28
CVE-2026-41160 EspoCRM: Broken Access Control / IDOR in Note Pinning API allows unauthorized modification of notes — espocrm CWE-284 4.3 Medium 2026-05-28
CVE-2026-33741 EspoCRM: Stored XSS via SVG attachment loading same-origin JavaScript — espocrm CWE-79 6.8 Medium 2026-05-19
CVE-2026-33733 EspoCRM has Admin TemplateManager path traversal that allows arbitrary file read write and delete — espocrm CWE-23 7.2 High 2026-04-22
CVE-2026-33656 EspoCRM vulnerable to authenticated RCE via Formula with path traversal in attachment `sourceId`, exploitable by admin user — espocrm CWE-22 9.1 Critical 2026-04-22
CVE-2026-33740 EspoCRM: Email importEml can import and delete another user's attachment by raw fileId — espocrm CWE-639 5.4 Medium 2026-04-13
CVE-2026-33659 EspoCRM: SSRF via DNS Rebinding in Attachment fromImageUrl Endpoint Allows Internal Network Access — espocrm CWE-918 3.5 Low 2026-04-13
CVE-2026-33657 EspoCRM: Stored HTML injection in email notifications about stream notes via unescaped post field — espocrm CWE-80 4.6 Medium 2026-04-13
CVE-2026-33534 EspoCRM has authenticated SSRF via internal-host validation bypass using alternative IPv4 notation — espocrm CWE-918 4.3 Medium 2026-04-13
CVE-2020-37094 EspoCRM 5.7.0 < 5.9.0 - Two-Factor Authentication Bypass via Auth Token Reuse Between Accounts with Identical Passwords — EspoCRM CWE-303 8.1 High 2026-02-03
CVE-2025-59428 EspoCRM allows arbitrary user creation via stored SVG injection and CSRF — espocrm CWE-352 5.4 Medium 2025-10-14
CVE-2025-52892 EspoCRM is vulnerable to access denial through double slash in URI corrupting router cache — espocrm CWE-444 4.5 Medium 2025-08-05
CVE-2025-52575 EspoCRM vulnerable to LDAP Injection through Improper Neutralization of Special Elements — espocrm CWE-90 6.5 Medium 2025-07-21
CVE-2025-32390 EspoCRM vulnerable to HTML Injection into phishing, which may lead to account takeover — espocrm CWE-74 4.6AI Medium AI 2025-05-12
CVE-2025-32789 EspoCRM Allows Potential Disclosure of Sensitive Information in the User Sorting Function — espocrm CWE-200 3.1 Low 2025-04-16
CVE-2025-32385 EspoCRM allows unrestricted Embedding in Iframe dashlet — espocrm CWE-1021 5.3 Medium 2025-04-15
CVE-2024-24818 EspoCRM weakness in "Forgot password" — espocrm CWE-610 5.9 Medium 2024-02-29
CVE-2023-46736 Server-Side Request Forgery in espocrm — espocrm CWE-918 5.3 Medium 2023-12-05
CVE-2023-5966 Unrestricted Upload of File with Dangerous Type in EspoCRM — EspoCRM CWE-434 4.7 Medium 2023-11-30
CVE-2023-5965 Unrestricted Upload of File with Dangerous Type in EspoCRM — EspoCRM CWE-434 4.7 Medium 2023-11-30
CVE-2021-3539 EspoCRM Avatar Persistent XSS — EspoCRM CWE-79 6.3 Medium 2021-08-04

This page lists every published CVE security advisory associated with EspoCRM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.