Small crm
This hub aggregates every CVE we track for Small crm, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
27
CVEs tracked
1
Critical
9
High
0
In CISA KEV
Severity distribution
MEDIUM15HIGH9LOW2CRITICAL1
Monthly trend
0
0
3
0
1
0
0
2
0
1
0
5
0
4
1
0
0
0
0
0
0
0
0
1
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Small crm.
- CVE-2026-90575PHPGurukul Small CRM Login Success login.php unserialize deserialization3.7
- CVE-2025-15390PHPGurukul Small CRM edit-user.php authorization6.3
- CVE-2024-44648PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php.6.5
- CVE-2024-44644PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php.6.5
- CVE-2024-44641PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php.6.5
- CVE-2024-44647PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via the aremark parameter in manage-tickets.php.6.1
- CVE-2025-11053PHPGurukul Small CRM forgot-password.php sql injection7.3
- CVE-2025-10664PHPGurukul Small CRM create-ticket.php sql injection7.3
- CVE-2025-10114PHPGurukul Small CRM profile.php sql injection7.3
- CVE-2025-10079PHPGurukul Small CRM get-quote.php sql injection7.3
- CVE-2025-9834PHPGurukul Small CRM registration.php cross site scripting3.5
- CVE-2025-50484Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to execute a session hijacking attack.7.1
- CVE-2025-5227PHPGurukul Small CRM manage-tickets.php sql injection7.3
- CVE-2025-5226PHPGurukul Small CRM change-password.php sql injection7.3
- CVE-2024-48170PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload injected into the name in the profile.php.5.4
Product normalization is registry-driven with AI assist and human review. How it works