Vulnerabilities > Espocrm > Low
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-08-04 | CVE-2021-3539 | Cross-site Scripting vulnerability in Espocrm EspoCRM 6.1.6 and prior suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. | 3.5 |
2019-08-05 | CVE-2019-14546 | Cross-site Scripting vulnerability in Espocrm An issue was discovered in EspoCRM before 5.6.9. | 3.5 |
2019-08-05 | CVE-2019-14547 | Cross-site Scripting vulnerability in Espocrm An issue was discovered in EspoCRM before 5.6.9. | 3.5 |
2019-08-05 | CVE-2019-14548 | Cross-site Scripting vulnerability in Espocrm An issue was discovered in EspoCRM before 5.6.9. | 3.5 |
2019-08-05 | CVE-2019-14549 | Cross-site Scripting vulnerability in Espocrm An issue was discovered in EspoCRM before 5.6.9. | 3.5 |
2019-08-05 | CVE-2019-14550 | Cross-site Scripting vulnerability in Espocrm An issue was discovered in EspoCRM before 5.6.9. | 3.5 |
2018-09-21 | CVE-2018-17301 | Cross-site Scripting vulnerability in Espocrm 5.3.6 Reflected XSS exists in client/res/templates/global-search/name-field.tpl in EspoCRM 5.3.6 via /#Account in the search panel. | 3.5 |
2014-10-20 | CVE-2014-8330 | Cross-Site Scripting vulnerability in Espocrm Cross-site scripting (XSS) vulnerability in EspoCRM allows remote authenticated users to inject arbitrary web script or HTML via the Name field in a new account. | 3.5 |