Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Crmeb

First CVE: Oct 23, 2020Active for: 6 yearsTotal CVEs: 37
56.0
VTI Score
TOP TARGET

Crmeb develops a focused e-commerce and customer relationship management platform available in both core and Java variants, with a concentrated vulnerability footprint that belies significant prominence in the landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the web-application and data-access demands of its business-logic codebase. The exposure recurs consistently across input handling and service integration boundaries through weakness classes including SQL injection, server-side request forgery, deserialization of untrusted data, improper authorization, and injection-based flaws, patterns typical of e-commerce platforms that blend customer-facing transaction processing with backend system interconnection. Defenders should prioritize this vendor's security updates despite its narrow product scope, as the recurring weakness classes represent direct pathways to data compromise and lateral movement. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
37
Total CVEs
More Total CVEs than 98% of tracked vendors
3.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 94% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Crmeb over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 23, 2020
5 years ago
Most Recent CVE
Feb 2, 2026
172 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (37 CVEs).

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-36837HIGH
SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.
Jun 5, 20247.538NOYES
CVE-2023-30185CRITICAL
CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.
May 8, 20239.833NONO
CVE-2020-25466CRITICAL
A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.
Oct 23, 20209.833NONO
CVE-2026-1202CRITICAL
A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file crmeb/app/api/controller/v1/LoginController.php. Performing a
Jan 20, 20269.831NONO
CVE-2023-1608CRITICAL
A vulnerability was found in Zhong Bang CRMEB Java up to 1.3.4. It has been declared as critical. This vulnerability affects the function getAdminList of the file /api/admin/store/
Mar 23, 20239.831NONO
CVE-2023-3232CRITICAL
A vulnerability was found in Zhong Bang CRMEB up to 4.6.0 and classified as critical. This issue affects some unknown processing of the file /api/wechat/app_auth of the component I
Jun 14, 20239.830NONO
CVE-2026-1203HIGH
A weakness has been identified in CRMEB up to 5.6.3. The impacted element is the function remoteRegister of the file crmeb/app/services/user/LoginServices.php of the component JSON
Jan 20, 20268.129NONO
CVE-2023-3234CRITICAL
A vulnerability was found in Zhong Bang CRMEB up to 4.6.0. It has been declared as problematic. Affected by this vulnerability is the function put_image of the file api/controller/
Jun 14, 20239.828NONO
CVE-2025-11288HIGH
A security flaw has been discovered in CRMEB up to 5.6. This issue affects some unknown processing of the file /adminapi/product/product of the component GET Parameter Handler. Per
Oct 5, 20258.827NONO
CVE-2025-10391HIGH
A security vulnerability has been detected in CRMEB up to 5.6.1. The impacted element is the function testOutUrl of the file app/services/out/OutAccountServices.php. The manipulati
Sep 14, 20258.827NONO
View all 37 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products37 CVEs
19%
59%
22%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network36 (97.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (2.7%)
Attack Complexity
Low35 (94.6%)
High2 (5.4%)
Unknown0 (0.0%)
User Interaction
None36 (97.3%)
Unknown0 (0.0%)
Required1 (2.7%)
Privileges Required
Low12 (32.4%)
High5 (13.5%)
None20 (54.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (37 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.7% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Crmeb.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Crmeb — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Crmeb's Products

View all 2 CNAs →

Top CWEs