CVE Tools

Crm

99 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Crm, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Crm CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Crm CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-021
2025-030
2025-040
2025-051
2025-061
2025-072
2025-080
2025-090
2025-100
2025-111
2025-1220
2026-013
2026-021
2026-031
2026-0438
2026-054
2026-061
2026-074
2026-080
2026-099

Severity

How the 99 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1112%
  • High4548%
  • Medium3335%
  • Low44%

Latest CVEs

The 15 most recently published vulnerabilities affecting Crm.

  1. CVE-2021-48008Chanjet CRM SQL Injection via get_usedspace.php7.5
  2. CVE-2026-92418ChangeWeDer crm Save Endpoint customer.serve.js cross site scripting3.5
  3. CVE-2026-92402ChangeWeDer crm top.upstudy.crm.controller.UserController UserController.java index authorization6.3
  4. CVE-2026-92401ChangeWeDer crm improper authentication7.3
  5. CVE-2026-86172DefaultFuction CRM delete.php sql injection6.3
  6. CVE-2026-86171DefaultFuction CRM delete.php sql injection6.3
  7. CVE-2026-86170DefaultFuction CRM edit.php sql injection6.3
  8. CVE-2026-53761Frappe CRM: Authentication Bypass via Logged Invitation Keys in crm/api—
  9. CVE-2026-84111Chanjet CRM jxf_dump_table.php sql injection7.3
  10. CVE-2026-58411ChurchCRM has Reflected Cross-Site Scripting (XSS) via unsanitized request parameter names and values—
  11. CVE-2026-58410ChurchCRM: Improper object-level authorization allows low-privileged users to read and modify other families’ records7.1
  12. CVE-2026-58409ChurchCRM: Authenticated Remote Code Execution (RCE) via Malicious Plugin Upload9.1
  13. CVE-2026-58408ChurchCRM : Broken Access Control in `CSVCreateFile.php` Allows Low-Privileged Users to Export All Members' PII6.5
  14. CVE-2026-11456Chanjet CRM HTTP GET Request jxf_dump_systable.php sql injection7.3
  15. CVE-2026-44548ChurchCRM: CSRF via legacy GET-delete pages (FundRaiserDelete.php, PropertyTypeDelete.php, NoteDelete.php)8.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store