VulnSea

espocrm has 4 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 5.0 (medium).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.0
Publish → KEV
Last 90 days
3 prev 0

Products

  • EspoCRM 4
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

espocrm vulnerabilities

CVEs affecting espocrm, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-92298Medium· 4.8
6d ago

EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and campaign URLs instead of a cryptographically secure generator

EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and campaign URLs instead of a cryptographically secure generator. Remote unauthenticated attackers can guess these roughly 3…

SunlitEspoCRM · EspoCRMEPSS 0.32%via NVD
CVE-2026-90934Medium· 4.3
1w ago

EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints that allows authenticated users to read restricted email addresses

EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints that allows authenticated users to read restricted email addresses. Attackers can recover hidden attendee emails by ex…

Sunlitespocrm · espocrmEPSS 0.18%via NVD
CVE-2026-88896Medium· 5.3
1w ago

EspoCRM before 10.0.4 is vulnerable to server-side request forgery

EspoCRM before 10.0.4 is vulnerable to server-side request forgery. HostCheck::ipAddressIsNotInternal(), which validates outbound URLs to block requests to internal/private IP addresses, strips ::ffff: (IPv4-mapped IPv6) prefixes but doe…

Sunlitespocrm · espocrmEPSS 0.34%via NVD
CVE-2020-37094High· 8.1
7mo ago

EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to bypass two-factor authentication by exploiting token-to-password-hash mapping in application/Espo/Core/Utils/Authent…

EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to bypass two-factor authentication by exploiting token-to-password-hash mapping in application/Espo/Core/Utils/Authent…

Twilightespocrm · espocrmEPSS 0.47%via NVD
espocrm vulnerabilities (CVEs) · VulnSea