Total CVEs

125,880

Critical Severity

2,277

High Severity

7,888

Last 7 Days

1,158
Quick preset (or use dates below)
Clear Filters
Showing 121 - 140 of 612 CVEs
CVE-2026-24559 MEDIUM - 5.4

Insertion of Sensitive Information Into Sent Data vulnerability in CRM Perks Integration for Contact Form 7 HubSpot cf7-hubspot allows Retrieve Embedded Sensitive Data.This issue affects Integration for Contact Form 7 HubSpot: from n/a through <= 1.4.3.

Vendor: CRM Perks
Product: Integration for Contact Form 7 HubSpot
Published: Jan 23, 2026
Source: NVD
CVE-2025-67968 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in InspiryThemes Real Homes CRM realhomes-crm allows Using Malicious Files.This issue affects Real Homes CRM: from n/a through <= 1.0.0.

Vendor: InspiryThemes
Product: Real Homes CRM
Published: Jan 22, 2026
Source: NVD
CVE-2025-62106 HIGH - 8.8

Missing Authorization vulnerability in Mario Peshev WP-CRM System wp-crm-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-CRM System: from n/a through <= 3.4.5.

Vendor: Mario Peshev
Product: WP-CRM System
Published: Jan 22, 2026
Source: NVD
CVE-2026-21926 HIGH - 7.5

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-25.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Siebel CRM Deployment. Successf...

Published: Jan 20, 2026
Source: NVD
CVE-2026-1203 MEDIUM - 5.6

A weakness has been identified in CRMEB up to 5.6.3. The impacted element is the function remoteRegister of the file crmeb/app/services/user/LoginServices.php of the component JSON Token Handler. Executing a manipulation of the argument uid can lead to improper authentication. The attack may be perf...

Published: Jan 20, 2026
Source: NVD
CVE-2026-1202 HIGH - 7.3

A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file crmeb/app/api/controller/v1/LoginController.php. Performing a manipulation of the argument openId results in improper authentication. The attack is possible to be carried out remotel...

Published: Jan 20, 2026
Source: NVD
CVE-2026-0725 MEDIUM - 4.4

The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, ...

Published: Jan 17, 2026
Source: NVD
CVE-2026-0820 MEDIUM - 5.3

The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference due to missing capability checks on the wc_upload_and_save_signature_handler function in all versions up to, and including, 4.1116. This makes it possible for a...

Published: Jan 17, 2026
Source: NVD
CVE-2021-47779 HIGH - 7.2

Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject malicious scripts. Attackers can craft a specially designed ticket message with embedded JavaScript that triggers when an administrator copies the text...

Vendor: Dolibarr
Product: CRM
Published: Jan 16, 2026
Source: NVD
CVE-2025-14854 MEDIUM - 5.4

The WP-CRM System plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on the wpcrm_get_email_recipients and wpcrm_system_ajax_task_change_status AJAX functions in all versions up to, and including, 3.4.5. This makes it possible for authenticated attackers, with...

Published: Jan 14, 2026
Source: NVD
CVE-2023-53985 MEDIUM - 6.1

Zstore, now referred to as Zippy CRM, 6.5.4 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts through unvalidated input parameters. Attackers can submit crafted payloads in manual insertion points to execute arbitrary JavaScript code in victim&...

Published: Jan 13, 2026
Source: NVD

Imaster's MEMS Events CRM contains an SQL injection vulnerability in ‘phone’ parameter in ‘/memsdemo/login.php’.

Published: Jan 12, 2026
Source: NVD

Imaster's MEMS Events CRM contains an SQL injection vulnerability in‘keyword’ parameter in ‘/memsdemo/exchange_offers.php’.

Published: Jan 12, 2026
Source: NVD
CVE-2025-14901 MEDIUM - 6.5

The Bit Form – Contact Form Plugin plugin for WordPress is vulnerable to unauthorized workflow execution due to missing authorization in the triggerWorkFlow function in all versions up to, and including, 2.21.6. This is due to a logic flaw in the nonce verification where the security check only bloc...

Published: Jan 07, 2026
Source: NVD
CVE-2025-59467 HIGH - 7.5

A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. This plugin is disabled by default. Affected Products: UCRM Argentina AFIP invoices P...

Published: Jan 05, 2026
Source: NVD
CVE-2025-15443 HIGH - 7.2

A vulnerability was identified in CRMEB up to 5.6.1. This issue affects some unknown processing of the file /adminapi/product/product_export. Such manipulation of the argument cate_id leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used. Th...

Vendor: crmeb
Product: crmeb
Published: Jan 04, 2026
Source: NVD
CVE-2025-15442 HIGH - 7.2

A vulnerability was determined in CRMEB up to 5.6.1. This vulnerability affects unknown code of the file /adminapi/export/product_list. This manipulation of the argument cate_id causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. T...

Vendor: crmeb
Product: crmeb
Published: Jan 04, 2026
Source: NVD
CVE-2025-15390 HIGH - 8.8

A security flaw has been discovered in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /admin/edit-user.php. The manipulation results in missing authorization. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.

Vendor: phpgurukul
Product: small_crm
Published: Dec 31, 2025
Source: NVD
CVE-2025-68928 MEDIUM - 5.4

Frappe CRM is an open-source customer relationship management tool. Prior to version 1.56.2, authenticated users could set crafted URLs in a website field, which were not sanitized, causing cross-site scripting. Version 1.56.2 fixes the issue. No known workarounds are available.

Vendor: frappe
Product: frappe_crm
Published: Dec 29, 2025
Source: NVD
CVE-2025-68590 CRITICAL - 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Integration for Contact Form 7 HubSpot cf7-hubspot allows Blind SQL Injection.This issue affects Integration for Contact Form 7 HubSpot: from n/a through <= 1.4.2.

Published: Dec 24, 2025
Source: NVD