VulnSea

5kcrm has 4 CVEs on record between 2024 and 2025. The median CVSS is 5.4 (medium), with 1 rated critical.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.4
Publish → KEV
Last 90 days
0 prev 0

Products

  • wukong_crm 4
4
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

5kcrm vulnerabilities

CVEs affecting 5kcrm, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2025-60828Medium· 6.5
11mo ago

WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine interface.

WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine interface.

Sunlit5kcrm · wukong_crmEPSS 0.36%via NVD
CVE-2025-8852Medium· 4.3
1y ago

A vulnerability was identified in WuKongOpenSource WukongCRM 11.0

A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation leads to information exposure through error message. It…

Sunlit5kcrm · wukong_crmEPSS 0.36%via NVD
CVE-2025-5521Medium· 4.3
1y ago

A vulnerability was found in WuKongOpenSource WukongCRM 9.0

A vulnerability was found in WuKongOpenSource WukongCRM 9.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /system/user/updataPassword. The manipulation leads to cross-site re…

Sunlit5kcrm · wukong_crmEPSS 0.31%via NVD
CVE-2024-23052Critical· 9.8
2y ago

An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.

An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.

Midnight5kcrm · wukong_crmEPSS 4.9%via NVD
5kcrm vulnerabilities (CVEs) · VulnSea