Opencrx is a customer relationship management and enterprise application platform whose vulnerability profile concentrates in a single, widely deployed product affecting organizations across various sectors. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes including cross-site scripting, improper authentication, code injection, XML external entity reference handling, and observable discrepancies that reflect the input-handling and access-control demands of a web-facing business application. Defenders should prioritize patching and access control for this platform; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opencrx over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-46502CRITICAL An issue in openCRX v.5.2.2 allows a remote attacker to read internal files and execute server side request forgery attack via insecure DocumentBuilderFactory. | Oct 30, 2023 | 9.8 | 24 | NO | NO |
CVE-2020-7378CRITICAL CRIXP OpenCRX version 4.30 and 5.0-20200717 and prior suffers from an unverified password change vulnerability. An attacker who is able to connect to the affected OpenCRX instance | Nov 24, 2020 | 9.1 | 23 | NO | NO |
CVE-2021-25959MEDIUM In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password reset functionality. This allows ex | Sep 29, 2021 | 6.1 | 21 | NO | NO |
CVE-2023-27151MEDIUM openCRX 5.2.0 was discovered to contain an HTML injection vulnerability for Search Criteria-Activity Number (in the Saved Search Activity) via the Name, Description, or Activity Nu | Feb 29, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-40817MEDIUM OpenCRX version 5.2.0 is vulnerable to HTML injection via the Product Configuration Name Field. | Nov 18, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-40816MEDIUM OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Milestone Name Field. | Nov 18, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-40815MEDIUM OpenCRX version 5.2.0 is vulnerable to HTML injection via the Category Creation Name Field. | Nov 18, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-40814MEDIUM OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Name Field. | Nov 18, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-40813MEDIUM OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Saved Search Creation. | Nov 18, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-40812MEDIUM OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Group Name Field. | Nov 18, 2023 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opencrx.
Media articles that mention a CVE ID that affects a product developed by Opencrx — matched by CVE ID, not by vendor name.