Cremecrm is a customer relationship management platform whose vulnerability profile centers on the application itself and concentrates on client-side and trust-boundary handling issues, specifically cross-site scripting and open-redirect flaws. These weakness classes reflect the input-validation and navigation-control demands of a web-facing CRM; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cremecrm over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-9283MEDIUM An XSS issue was discovered in CremeCRM 1.6.12. It is affected by 10 stored Cross-Site Scripting (XSS) vulnerabilities in the firstname, lastname, billing_address-address, billing_ | Sep 7, 2018 | 5.4 | 20 | NO | NO |
CVE-2018-14397MEDIUM An issue was discovered in Creme CRM 1.6.12. The organization creation page is affected by 9 stored cross-site scripting vulnerabilities involving the name, billing_address-address | Sep 7, 2018 | 5.4 | 20 | NO | NO |
CVE-2018-14396MEDIUM An issue was discovered in Creme CRM 1.6.12. The salesman creation page is affected by 10 stored cross-site scripting vulnerabilities involving the firstname, lastname, billing_add | Sep 7, 2018 | 5.4 | 20 | NO | NO |
CVE-2018-14398MEDIUM An issue was discovered in Creme CRM 1.6.12. The value of the cancel button uses the content of the HTTP Referer header, and could be used to trick a user into visiting a fake logi | Sep 7, 2018 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cremecrm.
Media articles that mention a CVE ID that affects a product developed by Cremecrm — matched by CVE ID, not by vendor name.