Daybydaycrm develops a focused customer relationship management platform whose vulnerability profile centers on web-application input handling and access-control weaknesses, including cross-site scripting, missing authorization checks, insufficient session management, and weak password policies. These recur across its core product line and reflect the authentication and client-side trust boundaries inherent to web-based CRM deployments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Daybydaycrm over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-22113HIGH In DayByDay CRM, versions 2.2.0 through 2.2.1 (latest) are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a use | Jan 13, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-22111HIGH In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled is able to change the password | Jan 5, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-22110HIGH In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user with privileges to update his password could change it to a | Jan 5, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-22112MEDIUM In DayByDay CRM, versions 1.1 through 2.2.1 (latest) suffer from an application-wide Client-Side Template Injection (CSTI). A low privileged attacker can input template injection p | Jan 13, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-22108MEDIUM In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the absence | Jan 5, 2022 | 4.3 | 19 | NO | NO |
CVE-2020-35706MEDIUM Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Project screen. | Dec 25, 2020 | 5.4 | 19 | NO | NO |
CVE-2020-35705MEDIUM Daybyday 2.1.0 allows stored XSS via the Name parameter to the New User screen. | Dec 25, 2020 | 5.4 | 19 | NO | NO |
CVE-2020-35704MEDIUM Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Lead screen. | Dec 25, 2020 | 5.4 | 19 | NO | NO |
CVE-2022-22107MEDIUM In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the appoint | Jan 5, 2022 | 4.3 | 18 | NO | NO |
CVE-2022-22109MEDIUM In Daybyday CRM, version 2.2.0 is vulnerable to Stored Cross-Site Scripting (XSS) vulnerability that allows low privileged application users to store malicious scripts in the title | Jan 5, 2022 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Daybydaycrm.
Media articles that mention a CVE ID that affects a product developed by Daybydaycrm — matched by CVE ID, not by vendor name.