Known Vulnerabilities for products from Fatfreecrm
Listed below are 11 of the newest known vulnerabilities associated with the vendor "Fatfreecrm".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-39281 json | fat_free_crm is a an open source, Ruby on Rails customer relationship management platform (CRM). In versions prior to 0.20.1 ... | 6.5 - MEDIUM | 2022-10-08 | 2022-10-11 |
| CVE-2019-10226 json | HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to the /co... | 5.4 - MEDIUM | 2019-06-10 | 2020-08-24 |
| CVE-2018-1000842 json | FatFreeCRM version <=0.14.1, >=0.15.0 <=0.15.1, >=0.16.0 <=0.16.3, >=0.17.0 <=0.17.2, ==0.18.0 contains a Cross Site Scriptin... | 6.1 - MEDIUM | 2018-12-20 | 2023-11-07 |
| CVE-2018-20975 json | Fat Free CRM before 0.18.1 has XSS in the tags_helper in app/helpers/tags_helper.rb. | 6.1 - MEDIUM | 2019-08-20 | 2019-08-26 |
| CVE-2015-1585 json | Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without... | Not Provided | 2015-02-19 | 2026-05-06 |
| CVE-2014-5441 json | Multiple cross-site scripting (XSS) vulnerabilities in app/views/layouts/application.html.haml in Fat Free CRM before 0.13.3 ... | Not Provided | 2014-09-12 | 2026-05-06 |
| CVE-2013-7249 json | Fat Free CRM before 0.12.1 does not restrict XML serialization, which allows remote attackers to obtain sensitive information... | Not Provided | 2014-01-02 | 2026-04-29 |
| CVE-2013-7225 json | Multiple SQL injection vulnerabilities in app/controllers/home_controller.rb in Fat Free CRM before 0.12.1 allow remote authe... | Not Provided | 2014-01-02 | 2026-04-29 |
| CVE-2013-7224 json | Fat Free CRM before 0.12.1 does not restrict JSON serialization, which allows remote attackers to obtain sensitive informatio... | Not Provided | 2014-01-02 | 2026-04-29 |
| CVE-2013-7223 json | Multiple cross-site request forgery (CSRF) vulnerabilities in Fat Free CRM before 0.12.1 allow remote attackers to hijack the... | Not Provided | 2014-01-02 | 2026-04-29 |
| CVE-2013-7222 json | config/initializers/secret_token.rb in Fat Free CRM before 0.12.1 has a fixed FatFreeCRM::Application.config.secret_token val... | Not Provided | 2014-01-02 | 2026-04-29 |
Known software with vulnerabilities from Fatfreecrm
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Fatfreecrm | Fatfreecrm | 0.18.0 |
| Application | Fatfreecrm | Fat Free Crm | 0.10.1 |