Customer Relationship Management
19 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Customer Relationship Management, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Customer Relationship Management CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 4 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 2 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 1 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 19 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High5
- Medium10
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting Customer Relationship Management.
- CVE-2025-707807FLYCMS/07FLY-CMS/07FlyCRM cross-site request forgery4.3
- CVE-2024-5716007FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html.4.3
- CVE-2024-5716107FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit.html4.3
- CVE-2024-990407FLYCMS/07FLY-CMS/07FlyCRM pictureUpload unrestricted upload4.7
- CVE-2024-990307FLYCMS/07FLY-CMS/07FlyCRM fileUpload unrestricted upload4.7
- CVE-2024-985607FLYCMS/07FLY-CMS/07FlyCRM System Settings Page cross site scripting2.4
- CVE-2024-985507FLYCMS/07FLY-CMS/07FlyCRM Module Plug-In sysmodule_1 uploadFile unrestricted upload4.7
- CVE-2023-502007FLY CRM Administrator Login Page sql injection7.3
- CVE-2023-305807FLY CRM User Profile cross site scripting3.5
- CVE-2023-27897Code Injection vulnerability in SAP CRM6.0
- CVE-2021-33676A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise confidentiality, integrity, or availability of th...7.2
- CVE-2018-2380SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" ...6.6
- CVE-2017-15296The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.8.8
- CVE-2017-15294The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.6.1
- CVE-2015-3980SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534.7.5
Product grouping is registry-driven, with AI assist and human review. How it works