Total CVEs

137,114

Critical Severity

3,291

High Severity

12,201

Last 7 Days

1,446
Quick preset (or use dates below)
Clear Filters
Showing 161 - 180 of 659 CVEs
CVE-2026-1734 MEDIUM - 5.3

A security flaw has been discovered in Zhong Bang CRMEB up to 5.6.3. This vulnerability affects unknown code of the file crmeb/app/api/controller/v1/CrontabController.php of the component crontab Endpoint. The manipulation results in missing authorization. The attack can be launched remotely. The ex...

Published: Feb 02, 2026
Source: NVD
CVE-2026-1733 MEDIUM - 4.3

A vulnerability was identified in Zhong Bang CRMEB up to 5.6.3. This affects the function detail/tidyOrder of the file /api/store_integral/order/detail/:uni. The manipulation of the argument order_id leads to improper authorization. The attack can be initiated remotely. The exploit is publicly avail...

Published: Feb 01, 2026
Source: NVD

ChurchCRM is an open-source church management system. Versions prior to 6.7.2 have a Stored Cross-Site Scripting (XSS) vulnerability occurs in Create Events in Church Calendar. Users with low privileges can create XSS payloads in the Description field. This payload is stored in the database, and whe...

Vendor: ChurchCRM
Product: CRM
Published: Jan 30, 2026
Source: NVD
CVE-2026-24854 HIGH - 8.8

ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in endpoint `/PaddleNumEditor.php` in ChurchCRM prior to version 6.7.2. Any authenticated user, including one with zero assigned permissions, can exploit SQL injection through the `PerID` parameter. Version 6....

Vendor: ChurchCRM
Product: CRM
Published: Jan 30, 2026
Source: NVD
CVE-2020-37006 HIGH - 8.2

berliCRM 1.0.24 contains a SQL injection vulnerability in the 'src_record' parameter that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through a crafted POST request to the index.php endpoint to potentially extract or modify database infor...

Vendor: crm-now GmbH
Product: berliCRM
Published: Jan 29, 2026
Source: NVD
CVE-2020-37004 HIGH - 8.2

Ultimate Project Manager CRM PRO 2.0.5 contains a blind SQL injection vulnerability that allows attackers to extract usernames and password hashes from the tbl_users database table. Attackers can exploit the /frontend/get_article_suggestion/ endpoint by crafting malicious search parameters to progre...

Vendor: codexcube
Product: Ultimate Project Manager CRM PRO
Published: Jan 29, 2026
Source: NVD
CVE-2026-24595 MEDIUM - 5.4

Missing Authorization vulnerability in zohocrm Zoho CRM Lead Magnet zoho-crm-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho CRM Lead Magnet: from n/a through <= 1.8.1.5.

Vendor: zohocrm
Product: Zoho CRM Lead Magnet
Published: Jan 23, 2026
Source: NVD
CVE-2026-24559 MEDIUM - 5.4

Insertion of Sensitive Information Into Sent Data vulnerability in CRM Perks Integration for Contact Form 7 HubSpot cf7-hubspot allows Retrieve Embedded Sensitive Data.This issue affects Integration for Contact Form 7 HubSpot: from n/a through <= 1.4.3.

Vendor: CRM Perks
Product: Integration for Contact Form 7 HubSpot
Published: Jan 23, 2026
Source: NVD
CVE-2025-67968 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in InspiryThemes Real Homes CRM realhomes-crm allows Using Malicious Files.This issue affects Real Homes CRM: from n/a through <= 1.0.0.

Vendor: InspiryThemes
Product: Real Homes CRM
Published: Jan 22, 2026
Source: NVD
CVE-2025-62106 HIGH - 8.8

Missing Authorization vulnerability in Mario Peshev WP-CRM System wp-crm-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-CRM System: from n/a through <= 3.4.5.

Vendor: Mario Peshev
Product: WP-CRM System
Published: Jan 22, 2026
Source: NVD
CVE-2026-21926 HIGH - 7.5

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-25.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Siebel CRM Deployment. Successf...

Published: Jan 20, 2026
Source: NVD
CVE-2026-1203 MEDIUM - 5.6

A weakness has been identified in CRMEB up to 5.6.3. The impacted element is the function remoteRegister of the file crmeb/app/services/user/LoginServices.php of the component JSON Token Handler. Executing a manipulation of the argument uid can lead to improper authentication. The attack may be perf...

Published: Jan 20, 2026
Source: NVD
CVE-2026-1202 HIGH - 7.3

A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file crmeb/app/api/controller/v1/LoginController.php. Performing a manipulation of the argument openId results in improper authentication. The attack is possible to be carried out remotel...

Published: Jan 20, 2026
Source: NVD
CVE-2026-0725 MEDIUM - 4.4

The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, ...

Published: Jan 17, 2026
Source: NVD
CVE-2026-0820 MEDIUM - 5.3

The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference due to missing capability checks on the wc_upload_and_save_signature_handler function in all versions up to, and including, 4.1116. This makes it possible for a...

Published: Jan 17, 2026
Source: NVD
CVE-2021-47779 HIGH - 7.2

Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject malicious scripts. Attackers can craft a specially designed ticket message with embedded JavaScript that triggers when an administrator copies the text...

Vendor: Dolibarr
Product: CRM
Published: Jan 16, 2026
Source: NVD
CVE-2025-14854 MEDIUM - 5.4

The WP-CRM System plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on the wpcrm_get_email_recipients and wpcrm_system_ajax_task_change_status AJAX functions in all versions up to, and including, 3.4.5. This makes it possible for authenticated attackers, with...

Published: Jan 14, 2026
Source: NVD
CVE-2023-53985 MEDIUM - 6.1

Zstore, now referred to as Zippy CRM, 6.5.4 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts through unvalidated input parameters. Attackers can submit crafted payloads in manual insertion points to execute arbitrary JavaScript code in victim&...

Published: Jan 13, 2026
Source: NVD

Imaster's MEMS Events CRM contains an SQL injection vulnerability in ‘phone’ parameter in ‘/memsdemo/login.php’.

Published: Jan 12, 2026
Source: NVD

Imaster's MEMS Events CRM contains an SQL injection vulnerability in‘keyword’ parameter in ‘/memsdemo/exchange_offers.php’.

Published: Jan 12, 2026
Source: NVD