Crm
This hub aggregates every CVE we track for Crm, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
99
CVEs tracked
11
Critical
45
High
0
In CISA KEV
Severity distribution
HIGH45MEDIUM33CRITICAL11LOW4
Monthly trend
0
0
0
0
1
0
0
1
1
2
0
0
0
1
20
3
1
1
38
4
1
4
0
9
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Crm.
- CVE-2021-48008Chanjet CRM SQL Injection via get_usedspace.php7.5
- CVE-2026-92418ChangeWeDer crm Save Endpoint customer.serve.js cross site scripting3.5
- CVE-2026-92402ChangeWeDer crm top.upstudy.crm.controller.UserController UserController.java index authorization6.3
- CVE-2026-92401ChangeWeDer crm improper authentication7.3
- CVE-2026-86172DefaultFuction CRM delete.php sql injection6.3
- CVE-2026-86171DefaultFuction CRM delete.php sql injection6.3
- CVE-2026-86170DefaultFuction CRM edit.php sql injection6.3
- CVE-2026-53761Frappe CRM: Authentication Bypass via Logged Invitation Keys in crm/api
- CVE-2026-84111Chanjet CRM jxf_dump_table.php sql injection7.3
- CVE-2026-58411ChurchCRM has Reflected Cross-Site Scripting (XSS) via unsanitized request parameter names and values
- CVE-2026-58410ChurchCRM: Improper object-level authorization allows low-privileged users to read and modify other families’ records7.1
- CVE-2026-58409ChurchCRM: Authenticated Remote Code Execution (RCE) via Malicious Plugin Upload9.1
- CVE-2026-58408ChurchCRM : Broken Access Control in `CSVCreateFile.php` Allows Low-Privileged Users to Export All Members' PII6.5
- CVE-2026-11456Chanjet CRM HTTP GET Request jxf_dump_systable.php sql injection7.3
- CVE-2026-44548ChurchCRM: CSRF via legacy GET-delete pages (FundRaiserDelete.php, PropertyTypeDelete.php, NoteDelete.php)8.1
Product normalization is registry-driven with AI assist and human review. How it works