Perfex CRM's vulnerability profile centers on a single customer relationship management platform that sits in organizations' sales and administrative workflows. The recurring exposures skew toward web-application security concerns—cross-site scripting, code injection, and unsafe file uploads—that reflect the platform's role as a data-handling and client-facing system, and its vulnerabilities show a moderate tendency toward public exploit availability. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Perfexcrm over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17976CRITICAL In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution. | Jan 26, 2018 | 9.8 | 47 | NO | YES |
CVE-2025-10346MEDIUM HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a
stored HTML injection due to lack of proper validation of user input by
sending a POST request in the parameters | Sep 29, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-10345MEDIUM HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a
stored HTML injection due to lack of proper validation of user input by
sending a POST request in the parameters | Sep 29, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-10344MEDIUM HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a
stored HTML injection due to lack of proper validation of user input by
sending a POST request in the parameters | Sep 29, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-10343MEDIUM HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a
stored HTML injection due to lack of proper validation of user input by
sending a POST request in the parameter | Sep 29, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-10342MEDIUM HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a
stored HTML injection due to lack of proper validation of user input by
sending a POST request in the parameter | Sep 29, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-10341MEDIUM HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a
stored HTML injection due to lack of proper validation of user input by
sending a POST request in the parameter | Sep 29, 2025 | 6.1 | 21 | NO | NO |
CVE-2021-40303MEDIUM perfex crm 1.10 is vulnerable to Cross Site Scripting (XSS) via /clients/profile. | Nov 8, 2022 | 5.4 | 20 | NO | NO |
CVE-2020-28961MEDIUM Perfex CRM v2.4.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component ./clients/client via the company name parameter. | Oct 22, 2021 | 5.4 | 19 | NO | NO |
CVE-2025-3219MEDIUM A vulnerability was found in CodeCanyon Perfex CRM 3.2.1. It has been classified as problematic. Affected is an unknown function of the file /perfex/clients/project/2 of the compon | Apr 4, 2025 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Perfexcrm.
Media articles that mention a CVE ID that affects a product developed by Perfexcrm — matched by CVE ID, not by vendor name.