Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CRM — Vulnerabilities & Security Advisories 87

All 87 CVE vulnerabilities found in CRM, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities associated with the crm product, focusing on general software weaknesses and specific tagging for enterprise customer relationship management systems. It aggregates data regarding common vulnerability types, including injection flaws, cross-site scripting, and authentication bypasses, covering the period from 2010 to the present. Visitors can use this resource to track vendor advisories, understand the historical prevalence of specific weakness classes within this product category, and look up a product's vulnerability history to assess long-term security posture. The content is curated to provide a clear view of the threat landscape without requiring deep technical expertise, allowing security teams to prioritize patching efforts based on the age and severity of disclosed issues. By consolidating these records, the page aims to reduce the time spent searching for relevant security information across disparate sources. The aggregation method ensures that both recent disclosures and older, unresolved issues are accessible for comparative analysis. This approach helps organizations identify patterns in vendor response times and the frequency of specific vulnerability types over time. Understanding these trends is crucial for risk management and for making informed decisions about software procurement and maintenance. The data presented here is intended for use by security analysts, risk managers, and IT administrators who need a comprehensive overview of the security status of crm solutions. All entries are verified for accuracy to ensure that the information reflects the actual state of known defects and their corresponding remediations.

Vendor: oroinc

CVE IDTitleCVSSSeverityPublished
CVE-2026-39333 ChurchCRM has Reflected XSS in DateStart/DateEnd parameters in FindFundRaiser.php CWE-79 8.7 High2026-04-07
CVE-2026-39332 ChurchCRM has Reflected Cross-Site Scripting (XSS) in GeoPage.php CWE-79 8.7 High2026-04-07
CVE-2026-39331 ChurchCRM has an API Authorization Bypass Allows Authenticated User to Deactivate, Modify, and Spam Arbitrary Families CWE-639 8.1 High2026-04-07
CVE-2026-39330 ChurchCRM has a Blind SQL injection in PropertyAssign.php CWE-89 8.8 High2026-04-07
CVE-2026-39329 ChurchCRM has a Blind SQL injection in EventNames.php CWE-89 8.8 High2026-04-07
CVE-2026-39328 ChurchCRM has Stored XSS in Social Profile Fields CWE-79 8.9 High2026-04-07
CVE-2026-39327 ChurchCRM has a SQL injection in MemberRoleChange.php CWE-89 8.8 High2026-04-07
CVE-2026-39326 ChurchCRM has a Blind SQL injection in PropertyTypeEditor.php CWE-89 8.8 High2026-04-07
CVE-2026-39325 ChurchCRM has a Blind SQL injection in SettingsUser.php CWE-89 7.2 High2026-04-07
CVE-2026-39318 ChurchCRM has a DDL SQL Injection in GroupPropsFormRowOps.php CWE-89 8.8 High2026-04-07
CVE-2026-39335 ChurchCRM has Stored XSS via Unescaped data-* Attributes in Group/Family Controls CWE-79 6.1 Medium2026-04-07
CVE-2026-35576 ChurchCRM has Stored Cross-Site Scripting (XSS) in Person Properties via PrintView.php CWE-79 8.7 High2026-04-07
CVE-2026-35575 ChurchCRM has Stored XSS in Group Name CWE-79 8.0 High2026-04-07
CVE-2026-35572 SSRF via Referer header in ChurchCRM allows server-side HTTP/HTTPS requests to arbitrary hosts CWE-918 7.1AIHighAI2026-04-07
CVE-2026-35573 ChurchCRM has a Path traversal leads to RCE CWE-22 9.1 Critical2026-04-07
CVE-2026-35574 ChurchCRM has a Stored XSS in Person Profile - Add a Note CWE-79 7.3 High2026-04-07
CVE-2026-35534 ChurchCRM has Stored XSS in PersonView.php via Facebook Field Attribute Injection CWE-79 7.6 High2026-04-07
CVE-2026-32880 ChurchCRM is vulnerable to Stored XSS through JSON handling in SystemSettings.php CWE-79 6.4 Medium2026-03-20
CVE-2026-26059 ChurchCRM has Stored Cross-Site Scripting (XSS) in GroupEditor.php CWE-79 5.4 -2026-02-19
CVE-2026-24855 ChurchCRM has Stored Cross-Site Scripting (XSS) in Create Events in Church Calendar, Leading to Account Takeover CWE-79 5.4AIMediumAI2026-01-30
CVE-2026-24854 Church CRM has SQL injection in PaddleNumEditor.php CWE-89 8.8 High2026-01-30
CVE-2021-47779 Dolibarr ERP-CRM 14.0.2 - Stored Cross-Site Scripting (XSS) / Privilege Escalation CWE-79 5.4 Medium2026-01-15
CVE-2025-68928 Frappe CRM vulnerable to authenticated XSS via website field CWE-79 5.4 Medium2025-12-29
CVE-2025-68275 ChurchCRM vulnerable to Stored XSS - Group name > Person Listing CWE-79 5.4AIMediumAI2025-12-17
CVE-2025-68401 ChurchCRM has Stored Cross-Site Scripting (XSS) vulnerability that leads to session theft and account takeover CWE-79 7.6AIHighAI2025-12-17
CVE-2025-68400 ChurchCRM vulnerable to time-based blind SQL Injection in ConfirmReportEmail.php CWE-89 8.8AIHighAI2025-12-17
CVE-2025-68399 ChurchCRM has Stored Cross-Site Scripting (XSS) In GroupEditor.php CWE-79 5.4AIMediumAI2025-12-17
CVE-2025-68112 ChurchCRM has SQL injection in EditEventAttendees.php CWE-89 9.6 Critical2025-12-17
CVE-2025-68111 ChurchCRM has SQL Injection in eGive Import Feature CWE-89 7.2 High2025-12-17
CVE-2025-68110 ChurchCRM discloses database information on error message CWE-200 10.0 Critical2025-12-17

All 87 known CVE vulnerabilities affecting CRM with full Chinese analysis, references, and POCs where available.