Total CVEs

125,880

Critical Severity

2,277

High Severity

7,888

Last 7 Days

1,158
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 101 - 120 of 137 CVEs
CVE-2026-3264 MEDIUM - 6.3

A vulnerability was determined in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. Affected by this issue is some unknown functionality of the component Administrative Interface. Executing a manipulation can lead to execution after redirect. The attack can be executed remotely. The...

Vendor: go2ismail
Product: free-crm
Published: Feb 26, 2026
Source: NVD
CVE-2026-2965 LOW - 2.4

A security flaw has been discovered in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.9. The affected element is an unknown function of the file /admin/SysModule/edit.html of the component System Extension Module. Performing a manipulation of the argument Title results in cross site scripting. The attac...

Published: Feb 23, 2026
Source: NVD
CVE-2019-25452 HIGH - 8.2

Dolibarr ERP/CRM 10.0.1 contains an SQL injection vulnerability in the elemid POST parameter of the viewcat.php endpoint that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted POST requests with malicious SQL payloads in the elemid parameter to extract s...

Vendor: Dolibarr
Product: Dolibarr ERP/CRM
Published: Feb 22, 2026
Source: NVD
CVE-2019-25450 HIGH - 7.1

Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through POST parameters. Attackers can inject malicious SQL through parameters like actioncode, demand_reason_id, and availability_id in car...

Vendor: Dolibarr
Product: Dolibarr ERP/CRM
Published: Feb 22, 2026
Source: NVD
CVE-2026-22356 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Automattic Jetpack CRM zero-bs-crm allows PHP Local File Inclusion.This issue affects Jetpack CRM: from n/a through <= 6.7.0.

Vendor: Automattic
Product: Jetpack CRM
Published: Feb 20, 2026
Source: NVD
CVE-2026-26059 MEDIUM - 5.4

ChurchCRM is an open-source church management system. In versions prior to 6.8.2, it was possible for an authenticated user with permission to edit groups to store a JavaScript payload that would execute when the group was viewed in the Group View. Version 6.8.2 fixes this issue.

Vendor: ChurchCRM
Product: CRM
Published: Feb 19, 2026
Source: NVD
CVE-2025-70981 CRITICAL - 9.8

CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter.

Vendor: fit2cloud
Product: cordys_crm
Published: Feb 12, 2026
Source: NVD
CVE-2025-69634 CRITICAL - 9.0

Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field in perms.php NOTE: this is disputed by a third party who indicates that exploitation can only occur if an unprivileged user knows the token of an admin user...

Published: Feb 12, 2026
Source: NVD
CVE-2026-0488 CRITICAL - 9.9

An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impac...

Vendor: sap
Product: netweaver_application_server_abap
Published: Feb 10, 2026
Source: NVD
CVE-2026-2141 MEDIUM - 6.3

A security flaw has been discovered in WuKongOpenSource WukongCRM up to 11.3.3. This affects an unknown part of the file gateway/src/main/java/com/kakarote/gateway/service/impl/PermissionServiceImpl.java of the component URL Handler. Performing a manipulation results in improper authorization. Remot...

Published: Feb 08, 2026
Source: NVD
CVE-2025-14079 MEDIUM - 5.3

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.3.5. This is due to missing capability checks on the eh_crm_ticket_general function combined with a shared nonce that is exposed to low-priv...

Vendor: elextensions
Product: ELEX WordPress HelpDesk & Customer Ticketing System
Published: Feb 05, 2026
Source: NVD
CVE-2020-37094 CRITICAL - 9.8

EspoCRM 5.8.5 contains an authentication vulnerability that allows attackers to access other user accounts by manipulating authorization headers. Attackers can decode and modify Basic Authorization and Espo-Authorization tokens to gain unauthorized access to administrative user information and privi...

Vendor: EspoCRM
Product: EspoCRM
Published: Feb 03, 2026
Source: NVD
CVE-2026-25137 CRITICAL - 9.1

The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the database manager without any authentication. This allows unauthorized actors to delete and download the entire database, including Odoos file store. Un...

Vendor: NixOS
Product: nixpkgs
Published: Feb 02, 2026
Source: NVD
CVE-2026-1734 MEDIUM - 5.3

A security flaw has been discovered in Zhong Bang CRMEB up to 5.6.3. This vulnerability affects unknown code of the file crmeb/app/api/controller/v1/CrontabController.php of the component crontab Endpoint. The manipulation results in missing authorization. The attack can be launched remotely. The ex...

Published: Feb 02, 2026
Source: NVD
CVE-2026-1733 MEDIUM - 4.3

A vulnerability was identified in Zhong Bang CRMEB up to 5.6.3. This affects the function detail/tidyOrder of the file /api/store_integral/order/detail/:uni. The manipulation of the argument order_id leads to improper authorization. The attack can be initiated remotely. The exploit is publicly avail...

Published: Feb 01, 2026
Source: NVD

ChurchCRM is an open-source church management system. Versions prior to 6.7.2 have a Stored Cross-Site Scripting (XSS) vulnerability occurs in Create Events in Church Calendar. Users with low privileges can create XSS payloads in the Description field. This payload is stored in the database, and whe...

Vendor: ChurchCRM
Product: CRM
Published: Jan 30, 2026
Source: NVD
CVE-2026-24854 HIGH - 8.8

ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in endpoint `/PaddleNumEditor.php` in ChurchCRM prior to version 6.7.2. Any authenticated user, including one with zero assigned permissions, can exploit SQL injection through the `PerID` parameter. Version 6....

Vendor: ChurchCRM
Product: CRM
Published: Jan 30, 2026
Source: NVD
CVE-2020-37006 HIGH - 8.2

berliCRM 1.0.24 contains a SQL injection vulnerability in the 'src_record' parameter that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through a crafted POST request to the index.php endpoint to potentially extract or modify database infor...

Vendor: crm-now GmbH
Product: berliCRM
Published: Jan 29, 2026
Source: NVD
CVE-2020-37004 HIGH - 8.2

Ultimate Project Manager CRM PRO 2.0.5 contains a blind SQL injection vulnerability that allows attackers to extract usernames and password hashes from the tbl_users database table. Attackers can exploit the /frontend/get_article_suggestion/ endpoint by crafting malicious search parameters to progre...

Vendor: codexcube
Product: Ultimate Project Manager CRM PRO
Published: Jan 29, 2026
Source: NVD
CVE-2026-24595 MEDIUM - 5.4

Missing Authorization vulnerability in zohocrm Zoho CRM Lead Magnet zoho-crm-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho CRM Lead Magnet: from n/a through <= 1.8.1.5.

Vendor: zohocrm
Product: Zoho CRM Lead Magnet
Published: Jan 23, 2026
Source: NVD