EspoCRM
3 known vulnerabilities in EspoCRM, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-92298 CVSS 6.3 medium EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and campaign URLs instead…
- CVE-2026-90934 CVSS 8.7 high EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints that allows…
- CVE-2026-88896 CVSS 6.9 medium EspoCRM before 10.0.4 is vulnerable to server-side request forgery. HostCheck::ipAddressIsNotInternal(), which validates outbound URLs to…