Total CVEs

125,880

Critical Severity

2,277

High Severity

7,888

Last 7 Days

1,158
Quick preset (or use dates below)
Clear Filters
Showing 1 - 20 of 612 CVEs
CVE-2026-36340 HIGH - 8.1

An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function

Published: Apr 30, 2026
Source: NVD
CVE-2026-7106 HIGH - 8.8

The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1.0.0. This is due to insufficient authorization checks in the hscrm_save_user_roles() function, which is hooked to the personal_options_update action accessible by an...

Published: Apr 27, 2026
Source: NVD
CVE-2026-33733 HIGH - 7.2

EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template management endpoints accept attacker-controlled `name` and `scope` values and pass them into template path construction without normalization or traversal filtering. As a result, an aut...

Vendor: espocrm
Product: espocrm
Published: Apr 22, 2026
Source: NVD
CVE-2026-33656 CRITICAL - 9.1

EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing updating attachment's sourceId thus allowing an authenticated admin to overwrite the `sourceId` field on `Attachment` entities. Because `sour...

Vendor: espocrm
Product: espocrm
Published: Apr 22, 2026
Source: NVD
CVE-2026-35451 MEDIUM - 5.7

Twenty is an open source CRM. Prior to 1.20.6, a Stored Cross-Site Scripting (XSS) vulnerability exists in the BlockNote editor component. Due to a lack of protocol validation in the FileBlock component and insufficient server-side inspection of block content, an attacker can inject a javascript: UR...

Vendor: twentyhq
Product: twenty
Published: Apr 21, 2026
Source: NVD
CVE-2026-31019 HIGH - 8.8

In the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict dangerous PHP functions related to system command execution. An authenticated user with permission to edit PHP content can bypass this filtering, resulting in full remote code...

Vendor: dolibarr
Product: dolibarr_erp\/crm
Published: Apr 21, 2026
Source: NVD
CVE-2026-31018 HIGH - 8.8

In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied consistently to all input parameters, allowing an authenticated user restricted to HTML/JavaScript editing to inject PHP code through unprotected inputs during website p...

Vendor: dolibarr
Product: dolibarr_erp\/crm
Published: Apr 21, 2026
Source: NVD
CVE-2026-6629 HIGH - 7.3

A vulnerability has been found in Metasoft ηΎŽη‰Ήθ½―δ»Ά MetaCRM up to 6.4.0. This vulnerability affects the function Statement.executeUpdate of the file sql.jsp of the component Interface. Such manipulation of the argument sql leads to sql injection. The attack can be launched remotely. The exploit has been...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6628 MEDIUM - 6.3

A flaw has been found in phili67 Ecclesia CRM up to 8.0.0. This affects the function ValidateInput of the file /v2/query/view/ of the component Query Viewer Component. This manipulation of the argument custom causes sql injection. The attack can be initiated remotely. The exploit has been published ...

Published: Apr 20, 2026
Source: NVD
CVE-2026-40593 MEDIUM - 4.8

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) renders stored usernames directly into an HTML input value attribute without applying htmlspecialchars(). An administrator can save a username containing HTML attribute-breaking charact...

Vendor: ChurchCRM
Product: CRM
Published: Apr 18, 2026
Source: NVD

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint validates only the username and password before returning the user's API key, bypassing the normal authentication flow that enforces account lockout and two-factor authenticatio...

Vendor: ChurchCRM
Product: CRM
Published: Apr 18, 2026
Source: NVD
CVE-2026-40581 HIGH - 8.1

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs permanent, irreversible deletion of family records and all associated data via a plain GET request with no CSRF token validation. An attacker can craft a ...

Vendor: ChurchCRM
Product: CRM
Published: Apr 18, 2026
Source: NVD
CVE-2026-40485 MEDIUM - 5.3

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/public/user/login) returns distinguishable HTTP response codes based on whether a username exists: 404 for non-existent users and 401 for valid users with incorrect passwords. An una...

Vendor: ChurchCRM
Product: CRM
Published: Apr 18, 2026
Source: NVD
CVE-2026-40484 CRITICAL - 9.1

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive contents and copies files from the Images/ directory into the web-accessible document root using recursiveCopyDirectory(), which performs no file exte...

Vendor: ChurchCRM
Product: CRM
Published: Apr 18, 2026
Source: NVD
CVE-2026-40483 MEDIUM - 5.4

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the Pledge Editor renders donation comment values directly into HTML input value attributes without escaping via htmlspecialchars(). An authenticated user with Finance permissions can inject HTML attribute-breaking cha...

Vendor: ChurchCRM
Product: CRM
Published: Apr 18, 2026
Source: NVD

ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::getMemberByScanString() via unsanitized $routeAndAccount concatenated into raw SQL. This issue has been fixed in version 7.2.0.

Vendor: ChurchCRM
Product: CRM
Published: Apr 18, 2026
Source: NVD

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoint loads and returns person records without performing object-level authorization checks. Although the legacy PersonView.php page enforces canEditPerson() restrictions, the API laye...

Vendor: ChurchCRM
Product: CRM
Published: Apr 18, 2026
Source: NVD

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT to PDF conversion process in odf.php concatenates the MAIN_ODT_AS_PDF configuration constant directly into a shell command passed to exec() without san...

Vendor: Dolibarr
Product: dolibarr
Published: Apr 17, 2026
Source: NVD
CVE-2026-38532 HIGH - 8.1

A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request.

Published: Apr 14, 2026
Source: NVD
CVE-2026-38530 HIGH - 8.1

A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request.

Published: Apr 14, 2026
Source: NVD