Known Vulnerabilities for Small Crm by Phpgurukul
Listed below are 8 of the newest known vulnerabilities associated with "Small Crm" by "Phpgurukul".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-84375 json | js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js... | Not Provided | 2026-09-01 | 2026-09-02 |
| CVE-2026-83619 json | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.7.0 until 0.... | Not Provided | 2026-09-01 | 2026-09-01 |
| CVE-2026-83615 json | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xm... | Not Provided | 2026-09-01 | 2026-09-01 |
| CVE-2026-83612 json | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.1 u... | Not Provided | 2026-09-01 | 2026-09-01 |
| CVE-2026-83606 json | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.9 u... | Not Provided | 2026-09-01 | 2026-09-01 |
| CVE-2026-82864 json | pdfme pdf-lib versions before 5.5.10 contain an unbounded buffer growth vulnerability in the DecodeStream.ensureBuffer() meth... | Not Provided | 2026-08-31 | 2026-08-31 |
| CVE-2026-82562 json | ### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a... | Not Provided | 2026-08-30 | 2026-08-31 |
| CVE-2026-82333 json | multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted text... | Not Provided | 2026-08-28 | 2026-08-31 |
| CVE-2026-82259 json | SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-81335 json | Baserow dispatches an Application Builder data source without acting on the result of its permission check. The dispatch and ... | Not Provided | 2026-08-27 | 2026-08-27 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Phpgurukul | Small Crm | 2.0 |