Erxes is an open-source customer relationship management and engagement platform with a niche presence in the vulnerability landscape, and its disclosures center on application-layer weaknesses in path traversal, improper access control, and cross-site scripting. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Erxes over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32853CRITICAL Erxes, an experience operating system (XOS) with a set of plugins, is vulnerable to cross-site scripting in versions 0.22.3 and prior. This results in client-side code execution. T | Feb 20, 2023 | 9.6 | 42 | NO | YES |
CVE-2024-57190CRITICAL Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any user, allowing them to talk to any | Jun 10, 2025 | 9.8 | 25 | NO | NO |
CVE-2024-57189MEDIUM In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHistoriesCreate GraphQL mutation handler. | Jun 10, 2025 | 5.4 | 16 | NO | NO |
CVE-2024-57186MEDIUM In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-file endpoint handler. | Jun 10, 2025 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Erxes.
Media articles that mention a CVE ID that affects a product developed by Erxes — matched by CVE ID, not by vendor name.