5kcrm develops WuKongCRM, a customer relationship management platform, whose vulnerability footprint centers on application-layer weaknesses including untrusted deserialization, cross-site request forgery, improper authorization, and exposure of sensitive information in error messages. Treat this as a narrow vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 5kcrm over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-23052CRITICAL An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component. | Feb 29, 2024 | 9.8 | 30 | NO | NO |
CVE-2026-2141HIGH A security flaw has been discovered in WuKongOpenSource WukongCRM up to 11.3.3. This affects an unknown part of the file gateway/src/main/java/com/kakarote/gateway/service/impl/Per | Feb 8, 2026 | 8.8 | 29 | NO | NO |
CVE-2025-5521HIGH A vulnerability was found in WuKongOpenSource WukongCRM 9.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /system/use | Jun 3, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-60828MEDIUM WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine interface. | Oct 8, 2025 | 6.5 | 25 | NO | NO |
CVE-2025-8852MEDIUM A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulatio | Aug 11, 2025 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 5kcrm.
Media articles that mention a CVE ID that affects a product developed by 5kcrm — matched by CVE ID, not by vendor name.