Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Espocrm

First CVE: Oct 20, 2014Active for: 12 yearsTotal CVEs: 40
35.7
VTI Score
Medium

Espocrm is a Customer Relationship Management platform that, despite a narrow product focus, occupies a prominent role in small-to-medium business deployments and integrations. Its vulnerability profile clusters around web-application input handling and access-control weaknesses—including cross-site scripting, server-side request forgery, unrestricted file uploads, path traversal, and authorization-bypass flaws—that are characteristic of complex, user-facing web applications handling multi-tenant data and integrations. These weakness classes reflect the platform's exposure to untrusted user input across forms, file handling, and API surfaces, and the risk surface expands with the breadth of integrations and customizations common in CRM deployments. Defenders using this platform should prioritize input validation and access-control controls during deployment and customization, and monitor vendor advisories closely given the product's direct exposure to end-user interaction. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
40
Total CVEs
More Total CVEs than 98% of tracked vendors
4.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Espocrm over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 20, 2014
11 years ago
Most Recent CVE
Apr 22, 2026
93 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (40 CVEs).

40 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-33534MEDIUM
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have an authenticated Server-Side Request Forgery (SSRF) vulnerability that allows
Apr 13, 20264.335NOYES
CVE-2026-33656CRITICAL
EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing updating attachment's sourceId
Apr 22, 20269.132NONO
CVE-2014-7985HIGH
Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter to install
Oct 31, 201410.030NONO
CVE-2020-37094HIGH
EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to bypass two-factor authentication by exploiting token-to-pas
Feb 3, 20268.128NONO
CVE-2022-38843HIGH
EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server. Attacker may execute these malicious f
Sep 16, 20228.828NONO
CVE-2019-14351HIGH
EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user password hash by 1 symbol at a time using specially crafted
Jul 28, 20198.827NONO
CVE-2022-38844HIGH
CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloads capable of executing system commands.
Sep 16, 20228.025NONO
CVE-2023-5966HIGH
An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, which could lead to arbitrary P
Nov 30, 20237.224NONO
CVE-2026-33733HIGH
EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template management endpoints accept attacker-controlled `name` and `scope
Apr 22, 20267.223NONO
CVE-2025-32390HIGH
EspoCRM is a free, open-source customer relationship management platform. Prior to version 9.0.8, HTML Injection in Knowledge Base (KB) articles leads to complete page defacement i
May 12, 20258.523NONO
View all 40 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products40 CVEs
68%
23%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network35 (87.5%)
Unknown4 (10.0%)
Physical0 (0.0%)
Adjacent Network1 (2.5%)
Attack Complexity
Low32 (80.0%)
High4 (10.0%)
Unknown4 (10.0%)
User Interaction
None16 (40.0%)
Unknown4 (10.0%)
Required20 (50.0%)
Privileges Required
Low19 (47.5%)
High4 (10.0%)
None13 (32.5%)
Unknown4 (10.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (40 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.5% of CVEs· 95th percentile
ExploitDB
1 CVE
2.5% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Espocrm.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Espocrm — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Espocrm's Products

View all 5 CNAs →

Top CWEs