📦 Espocrm

by Espocrm

🔍 What is Espocrm?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2020-37094

CRITICAL CVSS 9.8 Feb 3, 2026

EspoCRM 5.8.5 contains an authentication bypass vulnerability that allows attackers to access other user accounts by manipulating authorization headers. Attackers can decode and modify Basic Authoriza...

CVE-2023-5965

CRITICAL CVSS 9.1 Nov 30, 2023

This vulnerability allows authenticated privileged attackers to upload malicious zip files to EspoCRM servers, leading to arbitrary PHP code execution. Attackers with administrative access can comprom...

CVE-2025-32390

HIGH CVSS 8.5 May 12, 2025

EspoCRM versions before 9.0.8 contain an HTML injection vulnerability in Knowledge Base articles that allows authenticated users with read access to create malicious login page imitations. This enable...

CVE-2025-59428

MEDIUM CVSS 5.4 Oct 14, 2025

This vulnerability in EspoCRM allows attackers with Knowledge Base edit permissions to create arbitrary user accounts, including administrative accounts, through stored SVG injection combined with CSR...

CVE-2025-52892

MEDIUM CVSS 4.5 Aug 5, 2025

A path traversal vulnerability in EspoCRM versions 9.1.6 and below allows attackers to corrupt the Slim router's cache by accessing URLs with double slashes. This renders the instance unusable until a...