Espocrm is a Customer Relationship Management platform that, despite a narrow product focus, occupies a prominent role in small-to-medium business deployments and integrations. Its vulnerability profile clusters around web-application input handling and access-control weaknesses—including cross-site scripting, server-side request forgery, unrestricted file uploads, path traversal, and authorization-bypass flaws—that are characteristic of complex, user-facing web applications handling multi-tenant data and integrations. These weakness classes reflect the platform's exposure to untrusted user input across forms, file handling, and API surfaces, and the risk surface expands with the breadth of integrations and customizations common in CRM deployments. Defenders using this platform should prioritize input validation and access-control controls during deployment and customization, and monitor vendor advisories closely given the product's direct exposure to end-user interaction. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Espocrm over time
Signals from CVEs in this vendor scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33534MEDIUM EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have an authenticated Server-Side Request Forgery (SSRF) vulnerability that allows | Apr 13, 2026 | 4.3 | 35 | NO | YES |
CVE-2026-33656CRITICAL EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing updating attachment's sourceId | Apr 22, 2026 | 9.1 | 32 | NO | NO |
CVE-2014-7985HIGH Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter to install | Oct 31, 2014 | 10.0 | 30 | NO | NO |
CVE-2020-37094HIGH EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to bypass two-factor authentication by exploiting token-to-pas | Feb 3, 2026 | 8.1 | 28 | NO | NO |
CVE-2022-38843HIGH EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server. Attacker may execute these malicious f | Sep 16, 2022 | 8.8 | 28 | NO | NO |
CVE-2019-14351HIGH EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user password hash by 1 symbol at a time using specially crafted | Jul 28, 2019 | 8.8 | 27 | NO | NO |
CVE-2022-38844HIGH CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloads capable of executing system commands. | Sep 16, 2022 | 8.0 | 25 | NO | NO |
CVE-2023-5966HIGH An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, which could lead to arbitrary P | Nov 30, 2023 | 7.2 | 24 | NO | NO |
CVE-2026-33733HIGH EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template management endpoints accept attacker-controlled `name` and `scope | Apr 22, 2026 | 7.2 | 23 | NO | NO |
CVE-2025-32390HIGH EspoCRM is a free, open-source customer relationship management platform. Prior to version 9.0.8, HTML Injection in Knowledge Base (KB) articles leads to complete page defacement i | May 12, 2025 | 8.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (40 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Espocrm.
Media articles that mention a CVE ID that affects a product developed by Espocrm — matched by CVE ID, not by vendor name.