Known Vulnerabilities for CRMEB by ZhongBangKeJi
Listed below are 6 of the newest known vulnerabilities associated with "CRMEB" by "ZhongBangKeJi".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-88467 json | CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification function that returns the wrong type of value, ... | Not Provided | 2026-09-21 | 2026-10-01 |
| CVE-2026-85212 json | CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true ... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-85177 json | CRMEB through 6.0.0 fails to validate message ownership in the edit_message handler of MessageSystemController.php, allowing ... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-85040 json | A weakness has been identified in ZhongBangKeJi CRMEB up to 6.0.0. Affected by this vulnerability is the function eval of the... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-79426 json | An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated... | Not Provided | 2026-09-04 | 2026-09-08 |
| CVE-2026-79425 json | An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of CRMEB v6.0.0 allows atta... | Not Provided | 2026-09-15 | 2026-09-15 |