Yetiforce/yetiforce-crm
This hub aggregates every CVE we track for Yetiforce/yetiforce-crm, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
17
CVEs tracked
0
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM16HIGH1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Yetiforce/yetiforce-crm.
- CVE-2023-49508Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license parameter in the ...6.5
- CVE-2022-3002Cross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm5.4
- CVE-2022-3005Cross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm5.4
- CVE-2022-3004Cross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm5.4
- CVE-2022-3000Cross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm5.4
- CVE-2022-2924Cross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm5.4
- CVE-2022-2890Cross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm5.4
- CVE-2022-1340Cross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm5.4
- CVE-2022-2885Cross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm4.8
- CVE-2022-1411Unrestructed file upload in yetiforcecompany/yetiforcecrm6.1
- CVE-2022-0269Cross-Site Request Forgery (CSRF) in yetiforcecompany/yetiforcecrm8.0
- CVE-2021-4121Cross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm6.1
- CVE-2021-4117Business Logic Errors in yetiforcecompany/yetiforcecrm4.3
- CVE-2021-4116Cross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm5.4
- CVE-2021-4111Business Logic Errors in yetiforcecompany/yetiforcecrm4.3
Product normalization is registry-driven with AI assist and human review. How it works