Known Vulnerabilities for products from Daybydaycrm
Listed below are 11 of the newest known vulnerabilities associated with the vendor "Daybydaycrm".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-10283 json | Not Provided | 2026-06-01 | 2026-06-02 | |
| CVE-2026-10282 json | Not Provided | 2026-06-01 | 2026-06-01 | |
| CVE-2022-22113 json | In DayByDay CRM, versions 2.2.0 through 2.2.1 (latest) are vulnerable to Insufficient Session Expiration. When a password has... | 8.8 - HIGH | 2022-01-13 | 2022-02-25 |
| CVE-2022-22112 json | In DayByDay CRM, versions 1.1 through 2.2.1 (latest) suffer from an application-wide Client-Side Template Injection (CSTI). A... | 5.4 - MEDIUM | 2022-01-13 | 2022-01-20 |
| CVE-2022-22111 json | In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update... | 8.8 - HIGH | 2022-01-05 | 2022-01-08 |
| CVE-2022-22110 json | In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user with ... | 7.5 - HIGH | 2022-01-05 | 2022-01-21 |
| CVE-2022-22109 json | In Daybyday CRM, version 2.2.0 is vulnerable to Stored Cross-Site Scripting (XSS) vulnerability that allows low privileged ap... | 5.4 - MEDIUM | 2022-01-05 | 2022-01-08 |
| CVE-2022-22108 json | In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privil... | 4.3 - MEDIUM | 2022-01-05 | 2022-01-08 |
| CVE-2022-22107 json | In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privil... | 4.3 - MEDIUM | 2022-01-05 | 2022-01-08 |
| CVE-2020-35707 json | Daybyday 2.1.0 allows stored XSS via the Company Name parameter to the New Client screen. | 5.4 - MEDIUM | 2020-12-25 | 2020-12-28 |
| CVE-2020-35706 json | Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Project screen. | 5.4 - MEDIUM | 2020-12-25 | 2020-12-28 |
| CVE-2020-35705 json | Daybyday 2.1.0 allows stored XSS via the Name parameter to the New User screen. | 5.4 - MEDIUM | 2020-12-25 | 2020-12-28 |
| CVE-2020-35704 json | Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Lead screen. | 5.4 - MEDIUM | 2020-12-25 | 2020-12-28 |
Known software with vulnerabilities from Daybydaycrm
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Daybydaycrm | Daybyday | 2.1.0 |