Energycrm develops a focused customer relationship management product serving the energy sector, with the durable signal centered on web application input-handling issues, specifically cross-site scripting vulnerabilities. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Energycrm over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-40640MEDIUM Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS due to lack of proper validation of user input by sending a PO | Oct 10, 2025 | 5.4 | 21 | NO | NO |
CVE-2025-40646MEDIUM Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information about customers by intercepting HTTP requests and searching f | Oct 2, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-40643MEDIUM Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS due to lack of proper validation of user input by sending a PO | Oct 23, 2025 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Energycrm.
Media articles that mention a CVE ID that affects a product developed by Energycrm — matched by CVE ID, not by vendor name.