CVE Tools

Fatfreecrm

6 CVEs tracked since 2014. Since Jan 2014, none of them reached CISA KEV.

Fatfreecrm CVEs per month

Jan 2014 to Feb 2015. Point at a month, or focus the strip and use the arrow keys.
Fatfreecrm CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2014-0150
2014-02null or fewer
2014-03null or fewer
2014-04null or fewer
2014-05null or fewer
2014-06null or fewer
2014-07null or fewer
2014-08null or fewer
2014-09null or fewer
2014-10null or fewer
2014-11null or fewer
2014-12null or fewer
2015-01null or fewer
2015-0210

Products

The products that kept showing up in Fatfreecrm's monthly top three, with their CVEs summed over those months.

  1. Fat Free Crm62 months

Latest CVEs

The 11 most recently published vulnerabilities affecting Fatfreecrm.

  1. CVE-2022-39281Remote Denial of Service via Tasks endpoint in fat_free_crm6.5
  2. CVE-2018-20975Fat Free CRM before 0.18.1 has XSS in the tags_helper in app/helpers/tags_helper.rb.6.1
  3. CVE-2019-10226HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to the /comments URI. NOTE: the vendor disputes the significance of this report be...5.4
  4. CVE-2018-1000842FatFreeCRM version <=0.14.1, >=0.15.0 <=0.15.1, >=0.16.0 <=0.16.3, >=0.17.0 <=0.17.2, ==0.18.0 contains a Cross Site Scripting (XSS) vulnerability in commit 6d60bc8ed010c4eda05d6645c64849f415f68d65...6.1
  5. CVE-2015-1585Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token, as demonstrated by a crafted HTML page that cre...6.8
  6. CVE-2014-5441Multiple cross-site scripting (XSS) vulnerabilities in app/views/layouts/application.html.haml in Fat Free CRM before 0.13.3 allow remote attackers to inject arbitrary web script or HTML via the (1...4.3
  7. CVE-2013-7223Multiple cross-site request forgery (CSRF) vulnerabilities in Fat Free CRM before 0.12.1 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to t...6.8
  8. CVE-2013-7222config/initializers/secret_token.rb in Fat Free CRM before 0.12.1 has a fixed FatFreeCRM::Application.config.secret_token value, which makes it easier for remote attackers to spoof signed cookies b...5.0
  9. CVE-2013-7225Multiple SQL injection vulnerabilities in app/controllers/home_controller.rb in Fat Free CRM before 0.12.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the homepage ti...6.5
  10. CVE-2013-7249Fat Free CRM before 0.12.1 does not restrict XML serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for users/1.xml, a d...5.0
  11. CVE-2013-7224Fat Free CRM before 0.12.1 does not restrict JSON serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for users/1.json.5.0

The record

Peak rank
#28 in Jan 2014
Busiest month shown
Jan 2014, 5 CVEs
Months with a KEV entry
0 since Jan 2014
Monthly snapshots
2 since 2014
Fatfreecrm's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store