72CRM maintains a customer relationship management platform centered on its Wukong CRM product, with a focused vulnerability profile rooted in web application security. The recurring exposure involves input-handling and file-upload mechanisms characteristic of browser-facing business applications, spanning weaknesses such as unrestricted file uploads, cross-site request forgery, code injection, cross-site scripting, and SQL injection. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 72crm over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-46610HIGH 72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to execute arbitrary code via a crafte | Jan 10, 2023 | 8.8 | 37 | NO | NO |
CVE-2022-37181CRITICAL 72crm 9.0 has an Arbitrary file upload vulnerability. | Aug 24, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-37178HIGH An issue was discovered in 72crm 9.0. There is a SQL Injection vulnerability in View the task calendar. | Aug 24, 2022 | 8.8 | 28 | NO | NO |
CVE-2025-5879MEDIUM A vulnerability, which was classified as problematic, was found in WuKongOpenSource WukongCRM 9.0. This affects an unknown part of the file AdminSysConfigController.java of the com | Jun 9, 2025 | 5.4 | 16 | NO | NO |
CVE-2025-6106MEDIUM A vulnerability was found in WuKongOpenSource WukongCRM 9.0 and classified as problematic. This issue affects some unknown processing of the file AdminRoleController.java. The mani | Jun 16, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 72crm.
Media articles that mention a CVE ID that affects a product developed by 72crm — matched by CVE ID, not by vendor name.