Vulnerabilities > Espocrm > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-07-28 CVE-2019-14349 Cross-site Scripting vulnerability in Espocrm 5.6.4
EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for storing documents in the account tab.
network
low complexity
espocrm CWE-79
6.1
2019-07-28 CVE-2019-14331 Cross-site Scripting vulnerability in Espocrm
An issue was discovered in EspoCRM before 5.6.6.
network
low complexity
espocrm CWE-79
6.1
2019-07-28 CVE-2019-14330 Cross-site Scripting vulnerability in Espocrm
An issue was discovered in EspoCRM before 5.6.6.
network
low complexity
espocrm CWE-79
6.1
2019-07-28 CVE-2019-14329 Cross-site Scripting vulnerability in Espocrm
An issue was discovered in EspoCRM before 5.6.6.
network
low complexity
espocrm CWE-79
6.1
2019-07-18 CVE-2019-13643 Cross-site Scripting vulnerability in Espocrm
Stored XSS in EspoCRM before 5.6.4 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target pages.
network
low complexity
espocrm CWE-79
6.1
2018-09-21 CVE-2018-17302 Cross-site Scripting vulnerability in Espocrm 5.3.6
Stored XSS exists in views/fields/wysiwyg.js in EspoCRM 5.3.6 via a /#Email/view saved draft message.
network
low complexity
espocrm CWE-79
5.4
2018-09-21 CVE-2018-17301 Cross-site Scripting vulnerability in Espocrm 5.3.6
Reflected XSS exists in client/res/templates/global-search/name-field.tpl in EspoCRM 5.3.6 via /#Account in the search panel.
network
low complexity
espocrm CWE-79
5.4