Known Vulnerabilities for EspoCRM by EspoCRM
Listed below are 10 of the newest known vulnerabilities associated with "EspoCRM" by "EspoCRM".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-105833 json | EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\Service that allows users... | Not Provided | 2026-10-08 | 2026-10-08 |
| CVE-2026-105832 json | EspoCRM before 10.0.6 contains an authentication bypass vulnerability that accepts a login stopped at the second factor on ro... | Not Provided | 2026-10-08 | 2026-10-08 |
| CVE-2026-105831 json | EspoCRM before 10.0.6 contains a stored HTML injection vulnerability that allows unauthenticated attackers to inject HTML by ... | Not Provided | 2026-10-08 | 2026-10-08 |
| CVE-2026-92298 json | EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and campaign ... | Not Provided | 2026-09-16 | 2026-10-08 |
| CVE-2026-90934 json | EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints that a... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-88896 json | EspoCRM before 10.0.4 is vulnerable to server-side request forgery. HostCheck::ipAddressIsNotInternal(), which validates outb... | Not Provided | 2026-09-10 | 2026-09-15 |
| CVE-2026-33740 json | Not Provided | 2026-04-13 | 2026-04-22 | |
| CVE-2026-33733 json | Not Provided | 2026-04-22 | 2026-04-27 | |
| CVE-2026-33659 json | Not Provided | 2026-04-13 | 2026-04-22 | |
| CVE-2026-33657 json | Not Provided | 2026-04-13 | 2026-04-22 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Espocrm | Espocrm | 5.6.9 | |||
| Application | Espocrm | Espocrm | 5.6.8 | |||
| Application | Espocrm | Espocrm | 5.6.7 | |||
| Application | Espocrm | Espocrm | 5.6.6 | |||
| Application | Espocrm | Espocrm | 5.6.5 | |||
| Application | Espocrm | Espocrm | 5.6.4 | |||
| Application | Espocrm | Espocrm | 5.6.3 | |||
| Application | Espocrm | Espocrm | 5.6.2 | |||
| Application | Espocrm | Espocrm | 5.6.10 | |||
| Application | Espocrm | Espocrm | 5.6.1 | |||
| Application | Espocrm | Espocrm | 5.6.0 | |||
| Application | Espocrm | Espocrm | 5.5.6 | |||
| Application | Espocrm | Espocrm | 5.5.5 | |||
| Application | Espocrm | Espocrm | 5.5.4 | |||
| Application | Espocrm | Espocrm | 5.5.3 | |||
| Application | Espocrm | Espocrm | 5.5.2 | |||
| Application | Espocrm | Espocrm | 5.5.1 | |||
| Application | Espocrm | Espocrm | 5.5.0 | |||
| Application | Espocrm | Espocrm | 5.4.5 | |||
| Application | Espocrm | Espocrm | 5.4.4 |