Corebos is an open-source customer relationship management platform whose vulnerability footprint centers on web application and authentication weaknesses inherent to PHP-based business logic. The recurring exposure—spanning cross-site scripting, CSRF, improper authentication, PHP remote file inclusion, and formula injection in CSV export—reflects common attack surface areas in legacy and custom-built CRM systems, and vulnerabilities affecting the platform skew toward serious outcomes. Defenders should apply input validation and output encoding discipline throughout the platform's request handling and file-generation paths; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Corebos over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-3069CRITICAL Unverified Password Change in GitHub repository tsolucio/corebos prior to 8. | Jun 2, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-4446CRITICAL PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0. | Dec 13, 2022 | 9.8 | 29 | NO | NO |
CVE-2023-48029HIGH Corebos 8.0 and below is vulnerable to CSV Injection. An attacker with low privileges can inject a malicious command into a table. This vulnerability is exploited when an administr | Nov 17, 2023 | 8.0 | 22 | NO | NO |
CVE-2023-3075MEDIUM Cross-Site Request Forgery (CSRF) in GitHub repository tsolucio/corebos prior to 8. | Jun 2, 2023 | 6.5 | 22 | NO | NO |
CVE-2023-3073MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8 via evvtgendoc. | Jun 2, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-3074MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8. | Jun 2, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-3070MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8. | Jun 2, 2023 | 5.4 | 19 | NO | NO |
CVE-2018-1000547MEDIUM coreBOS version 7.0 and earlier contains a Incorrect Access Control vulnerability in Module: Contacts that can result in The error allows you to access records that you have no per | Jun 26, 2018 | 5.3 | 17 | NO | NO |
CVE-2023-1527MEDIUM Cross-site Scripting (XSS) - Generic in GitHub repository tsolucio/corebos prior to 8.0. | Mar 21, 2023 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Corebos.
Media articles that mention a CVE ID that affects a product developed by Corebos — matched by CVE ID, not by vendor name.