Vulnerabilidades em espocrm
24 resultadosAnálise Vexday
EspoCRM registra 17 vulnerabilidades na base, com apenas 1 crítica identificada e nenhuma sob exploração ativa documentada, reduzindo o risco imediato. A fraqueza predominante (CWE-639 – falha de autorização) sugere problemas de controle de acesso que podem ser explorados em contextos específicos. Os 3 eventos publicados nos últimos 90 dias indicam ciclo de descoberta contínuo, exigindo monitoramento regular de atualizações de segurança.
CVE-2026-33534MEDIUMEspoCRM has authenticated SSRF via internal-host validation bypass using alternative IPv4 notationEPSS 1.7%CVE-2023-5966MEDIUMUnrestricted Upload of File with Dangerous Type in EspoCRMEPSS 1.0%CVE-2023-5965MEDIUMUnrestricted Upload of File with Dangerous Type in EspoCRMEPSS 1.0%CVE-2025-52575MEDIUMEspoCRM vulnerable to LDAP Injection through Improper Neutralization of Special ElementsEPSS 0.7%CVE-2024-24818MEDIUMEspoCRM weakness in "Forgot password"EPSS 0.6%CVE-2026-33656CRITICALEspoCRM vulnerable to authenticated RCE via Formula with path traversal in attachment `sourceId`, exploitable by admin userEPSS 0.6%CVE-2026-33733HIGHEspoCRM has Admin TemplateManager path traversal that allows arbitrary file read write and deleteEPSS 0.6%CVE-2021-3539MEDIUMEspoCRM Avatar Persistent XSSEPSS 0.6%CVE-2020-37094HIGHEspoCRM 5.7.0 < 5.9.0 - Two-Factor Authentication Bypass via Auth Token Reuse Between Accounts with Identical PasswordsEPSS 0.5%CVE-2026-92298MEDIUMEspoCRM through 10.0.8 Weak Token Generation via rand()EPSS 0.4%CVE-2025-32789LOWEspoCRM Allows Potential Disclosure of Sensitive Information in the User Sorting FunctionEPSS 0.4%CVE-2026-33659LOWEspoCRM: SSRF via DNS Rebinding in Attachment fromImageUrl Endpoint Allows Internal Network AccessEPSS 0.4%CVE-2026-88896MEDIUMEspoCRM before 10.0.4 SSRF via IPv6 Transition Address BypassEPSS 0.4%CVE-2025-32390HIGHEspoCRM vulnerable to HTML Injection into phishing, which may lead to account takeoverEPSS 0.4%CVE-2026-41141MEDIUMEspoCRM: IDOR in EmailTemplate Prepare Endpoint Leaks Entity Data via Email Address LookupEPSS 0.4%CVE-2023-46736MEDIUMServer-Side Request Forgery in espocrmEPSS 0.4%CVE-2026-41160MEDIUMEspoCRM: Broken Access Control / IDOR in Note Pinning API allows unauthorized modification of notesEPSS 0.3%CVE-2026-90934HIGHEspoCRM before 10.0.4 Field-level Security Bypass via AttendeesEPSS 0.3%CVE-2026-33740MEDIUMEspoCRM: Email importEml can import and delete another user's attachment by raw fileIdEPSS 0.3%CVE-2025-32385MEDIUMEspoCRM allows unrestricted Embedding in Iframe dashletEPSS 0.3%