目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

crmperks 厂商漏洞列表 / CVE 中文分析 14

crmperks 厂商相关 14 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

CRMperks 是提供客户关系管理(CRM)解决方案的厂商,其产品帮助企业管理客户数据与业务流程。历史上,该系统常见漏洞包括远程代码执行(RCE)、跨站脚本攻击(XSS)和权限绕过等安全风险。截至最新统计,该厂商相关产品已记录14条CVE漏洞,主要集中在未经验证的输入处理和访问控制缺陷上,建议用户及时更新补丁并加强输入验证机制。

CVE IDタイトルCVSS深刻度公開日
CVE-2026-3831 Database for Contact Form 7, WPforms, Elementor forms <= 1.4.9 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Shortcode — Database for Contact Form 7, WPforms, Elementor formsCWE-862 4.3 Medium2026-04-01
CVE-2026-2599 Database for Contact Form 7, WPforms, Elementor forms <= 1.4.7 - Unauthenticated PHP Object Injection via 'download_csv' — Database for Contact Form 7, WPforms, Elementor formsCWE-502 9.8 Critical2026-03-05
CVE-2026-2568 WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.5 - Unauthenticated Stored Cross-Site Scripting — WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja FormsCWE-79 7.2 High2026-03-03
CVE-2026-0825 Database for Contact Form 7, WPforms, Elementor forms <= 1.4.5 - Missing Authorization to Unauthenticated Form Data Exfiltration via CSV Export — Database for Contact Form 7, WPforms, Elementor formsCWE-862 5.3 Medium2026-01-28
CVE-2025-7384 Database for Contact Form 7, WPforms, Elementor forms <= 1.4.3 - Unauthenticated PHP Object Injection to Arbitrary File Deletion — Database for Contact Form 7, WPforms, Elementor formsCWE-502 9.8 Critical2025-08-13
CVE-2025-7697 Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 - Unauthenticated PHP Object Injection via verify_field_val Function — Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja FormsCWE-502 9.8 Critical2025-07-19
CVE-2025-7696 Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.2.3 - Unauthenticated PHP Object Injection via verify_field_val Function — Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja FormsCWE-502 9.8 Critical2025-07-19
CVE-2025-4659 Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.4 - Unauthenticated Full Path Disclosure — Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja FormsCWE-200 5.3 Medium2025-05-30
CVE-2024-12443 CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout <= 1.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting — CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScoutCWE-79 6.4 Medium2024-12-16
CVE-2024-7484 CRM Perks Forms <= 1.1.3 - Authenticated (Administrator+) Arbitrary File Upload — CRM Perks Forms – WordPress Form BuilderCWE-434 7.2 High2024-08-06
CVE-2024-3715 Database for Contact Form 7, WPforms, Elementor forms <= 1.3.8 - Unauthenticated Stored Cross-Site Scripting — Database for Contact Form 7, WPforms, Elementor formsCWE-79 7.2 High2024-05-02
CVE-2024-2030 Database for Contact Form 7, WPforms, Elementor forms <= 1.3.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode — Database for Contact Form 7, WPforms, Elementor formsCWE-79 6.4 Medium2024-03-13
CVE-2024-1069 Contact Form Entries <= 1.3.2 - Authenticated (Administrator+) Arbitrary File Upload — Database for Contact Form 7, WPforms, Elementor formsCWE-434 7.2 High2024-01-31
CVE-2023-2836 CRM Perks Forms <= 1.1.1 - Authenticated (Admin+) Stored Cross-Site Scripting — CRM Perks Forms – WordPress Form BuilderCWE-79 4.4 Medium2023-05-31

本页汇总了 crmperks 厂商截至目前公开的全部 14 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。