Crmeb develops a focused e-commerce and customer relationship management platform available in both core and Java variants, with a concentrated vulnerability footprint that belies significant prominence in the landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the web-application and data-access demands of its business-logic codebase. The exposure recurs consistently across input handling and service integration boundaries through weakness classes including SQL injection, server-side request forgery, deserialization of untrusted data, improper authorization, and injection-based flaws, patterns typical of e-commerce platforms that blend customer-facing transaction processing with backend system interconnection. Defenders should prioritize this vendor's security updates despite its narrow product scope, as the recurring weakness classes represent direct pathways to data compromise and lateral movement. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Crmeb over time
Signals from CVEs in this vendor scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-36837HIGH SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file. | Jun 5, 2024 | 7.5 | 38 | NO | YES |
CVE-2023-30185CRITICAL CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php. | May 8, 2023 | 9.8 | 33 | NO | NO |
CVE-2020-25466CRITICAL A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. | Oct 23, 2020 | 9.8 | 33 | NO | NO |
CVE-2026-1202CRITICAL A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file crmeb/app/api/controller/v1/LoginController.php. Performing a | Jan 20, 2026 | 9.8 | 31 | NO | NO |
CVE-2023-1608CRITICAL A vulnerability was found in Zhong Bang CRMEB Java up to 1.3.4. It has been declared as critical. This vulnerability affects the function getAdminList of the file /api/admin/store/ | Mar 23, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-3232CRITICAL A vulnerability was found in Zhong Bang CRMEB up to 4.6.0 and classified as critical. This issue affects some unknown processing of the file /api/wechat/app_auth of the component I | Jun 14, 2023 | 9.8 | 30 | NO | NO |
CVE-2026-1203HIGH A weakness has been identified in CRMEB up to 5.6.3. The impacted element is the function remoteRegister of the file crmeb/app/services/user/LoginServices.php of the component JSON | Jan 20, 2026 | 8.1 | 29 | NO | NO |
CVE-2023-3234CRITICAL A vulnerability was found in Zhong Bang CRMEB up to 4.6.0. It has been declared as problematic. Affected by this vulnerability is the function put_image of the file api/controller/ | Jun 14, 2023 | 9.8 | 28 | NO | NO |
CVE-2025-11288HIGH A security flaw has been discovered in CRMEB up to 5.6. This issue affects some unknown processing of the file /adminapi/product/product of the component GET Parameter Handler. Per | Oct 5, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-10391HIGH A security vulnerability has been detected in CRMEB up to 5.6.1. The impacted element is the function testOutUrl of the file app/services/out/OutAccountServices.php. The manipulati | Sep 14, 2025 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (37 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Crmeb.
Media articles that mention a CVE ID that affects a product developed by Crmeb — matched by CVE ID, not by vendor name.