VulnSea

CRM vulnerabilities

CVEs whose affected-version data names the CRM package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

7 CVEsRSS

CVE-2021-48008High· 7.5
4d ago

Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the webservice endpoint

Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the webservice endpoint. Attackers can exploit the lack of inp…

TwilightChanjet Information Technology Co., Ltd. · CRMEPSS 0.34%via NVD
CVE-2026-92418Low· 3.5PoC
6d ago

A vulnerability was determined in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd

A vulnerability was determined in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects unknown code of the file src/main/resources/public/js/customerServe/customer.serve.js of the component Save Endp…

TwilightChangeWeDer · crmEPSS 0.33%via NVD
CVE-2026-92401High· 7.3
6d ago

A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd

A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects the function top.upstudy.crm.utils.LoginUserUtil.releaseUserIdFromCookie. The manipulation leads to improper aut…

TwilightChangeWeDer · crmEPSS 0.66%via NVD
CVE-2026-92402Medium· 6.3
6d ago

A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd

A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This issue affects the function index of the file UserController.java of the component top.upstudy.crm.controller.UserController. The …

SunlitChangeWeDer · crmEPSS 0.35%via NVD
CVE-2026-86172Medium· 6.3PoC
2w ago

A vulnerability was detected in DefaultFuction CRM 1.0.0

A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the a…

TwilightDefaultFuction · CRMEPSS 0.20%via NVD
CVE-2026-86171Medium· 6.3PoC
2w ago

A security vulnerability has been detected in DefaultFuction CRM 1.0.0

A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed fro…

TwilightDefaultFuction · CRMEPSS 0.19%via NVD
CVE-2026-86170Medium· 6.3PoC
2w ago

A weakness has been identified in DefaultFuction CRM 1.0.0

A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried…

TwilightDefaultFuction · CRMEPSS 0.19%via NVD
CRM vulnerabilities (CVEs) · VulnSea