Total CVEs

137,228

Critical Severity

3,305

High Severity

12,247

Last 7 Days

1,458
Quick preset (or use dates below)
Clear Filters
Showing 1 - 20 of 659 CVEs
CVE-2026-49765 CRITICAL - 9.8

Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions.

Vendor: CRM Perks
Product: Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms
Published: Jun 15, 2026
Source: NVD
CVE-2026-49763 CRITICAL - 9.8

Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.

Vendor: CRM Perks
Product: Integration for Contact Form 7 HubSpot
Published: Jun 15, 2026
Source: NVD
CVE-2026-49109 CRITICAL - 9.8

Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions.

Vendor: crm perks
Product: Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms
Published: Jun 15, 2026
Source: NVD
CVE-2026-49106 CRITICAL - 9.8

Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions.

Vendor: CRM Perks
Product: Integration for Contact Form 7 and Constant Contact
Published: Jun 15, 2026
Source: NVD
CVE-2026-49105 CRITICAL - 9.8

Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.

Vendor: CRM Perks
Product: WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms
Published: Jun 15, 2026
Source: NVD
CVE-2026-49104 CRITICAL - 9.8

Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions.

Vendor: CRM Perks
Product: Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms
Published: Jun 15, 2026
Source: NVD
CVE-2026-49085 CRITICAL - 9.8

Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.

Vendor: CRM Perks
Product: WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms
Published: Jun 15, 2026
Source: NVD
CVE-2026-42767 MEDIUM - 5.9

Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application. Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service. An attacker controlling a CMP server (or ac...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD

SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/user-login’ endpoint. The two-factor authentication (2FA) functionality can be accessed without prior authentication, allowing unauthenticated attackers to execute arbitrary SQL que...

Vendor: Nemon
Product: Nemon Trade Energy, Nemon Trade Energy CRM
Published: Jun 09, 2026
Source: NVD
CVE-2026-11619 MEDIUM - 6.3

A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy Filemanager. The manipulation leads to improper authorization. It is possible to initiate the atta...

Vendor: Dolibarr
Product: ERP CRM
Published: Jun 09, 2026
Source: NVD
CVE-2026-49141 HIGH - 7.1

WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body without tenant ownership v...

Vendor: ArnasDon
Product: wacrm
Published: Jun 08, 2026
Source: NVD
CVE-2026-11456 HIGH - 7.3

A vulnerability was identified in Chanjet CRM 1.0. This affects an unknown part of the file /tools/jxf_dump_systable.php of the component HTTP GET Request Handler. Such manipulation of the argument gblOrgID leads to sql injection. The attack may be launched remotely. The exploit is publicly availabl...

Vendor: Chanjet
Product: CRM
Published: Jun 07, 2026
Source: NVD
CVE-2026-8901 HIGH - 7.2

The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Submission Data in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes i...

Published: Jun 06, 2026
Source: NVD
CVE-2026-10771 HIGH - 7.3

A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zbkj/common/utils/RestTemplateUtil.java of the component base64 Qrcode Endpoint. The manipulation of the argument url results in server-side request forger...

Vendor: crmeb
Product: crmeb_java
Published: Jun 03, 2026
Source: NVD

A security vulnerability has been detected in 1Panel-dev CordysCRM up to 1.4.1. This impacts the function Save of the file src/main/java/cn/cordys/crm/system/service/ModuleFormService.java of the component ModuleFormController. The manipulation of the argument Description leads to cross site scripti...

Vendor: 1Panel-dev
Product: CordysCRM
Published: Jun 02, 2026
Source: NVD

A vulnerability has been found in 1Panel-dev CordysCRM up to 1.6.2. This affects an unknown function of the file backend/framework/src/main/java/cn/cordys/config/RequestParamTrimConfig.java. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit ha...

Vendor: 1Panel-dev
Product: CordysCRM
Published: Jun 02, 2026
Source: NVD
CVE-2026-10283 MEDIUM - 6.3

A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function of the component Setting Handler. Performing a manipulation results in missing authentication. Remote exploitation of the attack is possible. It is recommended to apply a patch to fix this issue.

Vendor: Bottelet
Product: DaybydayCRM
Published: Jun 01, 2026
Source: NVD
CVE-2026-10282 MEDIUM - 4.3

A security vulnerability has been detected in Bottelet DaybydayCRM up to 2.2.1. This impacts the function view of the file app/Http/Controllers/DocumentsController.php. Such manipulation leads to improper authorization. The attack may be launched remotely. It is best practice to apply a patch to res...

Vendor: Bottelet
Product: DaybydayCRM
Published: Jun 01, 2026
Source: NVD
CVE-2026-10215 MEDIUM - 4.3

A security vulnerability has been detected in Dolibarr ERP CRM up to 23.0.1. Impacted is the function checkUserAccessToObject of the file htdocs/holiday/class/api_holidays.class.php of the component Leave Request REST API. The manipulation leads to improper authorization. The attack may be initiated...

Vendor: Dolibarr
Product: ERP CRM
Published: Jun 01, 2026
Source: NVD
CVE-2026-10205 MEDIUM - 6.3

A security vulnerability has been detected in Metasoft 美特软件 MetaCRM 6.4.0. The impacted element is an unknown function of the file develop/systparam/softlogo/upload.jsp. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed publicly and m...

Vendor: Metasoft 美特软件
Product: MetaCRM
Published: Jun 01, 2026
Source: NVD