Small CRM Project maintains a focused customer-relationship-management application that, despite limited product scope, occupies a niche in deployments where it concentrates security exposure through application-layer weaknesses. Vulnerabilities affecting the vendor skew toward serious outcomes and recur consistently through input-handling flaws: cross-site scripting and SQL injection, which are characteristic of web applications where sanitization and parameterization practices are critical. Defenders should prioritize web-application security controls and input validation review for this product; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Small Crm Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-50035CRITICAL PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is directly used in the SQL query without any sanitization and the | Dec 29, 2023 | 9.8 | 30 | NO | NO |
CVE-2020-5511HIGH PHPGurukul Small CRM v2.0 was found vulnerable to authentication bypass via SQL injection when logging into the administrator login page. | Jan 8, 2020 | 8.8 | 25 | NO | NO |
CVE-2022-47073MEDIUM A cross-site scripting (XSS) vulnerability in the Create Ticket page of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into | Jan 26, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-34650MEDIUM PHPgurukl Small CRM v.1.0 is vulnerable to Cross Site Scripting (XSS). | Jun 28, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-45394MEDIUM Stored Cross-Site Scripting (XSS) vulnerability in the Company field in the "Request a Quote" Section of Small CRM v3.0 allows an attacker to store and execute malicious javascript | Oct 20, 2023 | 5.4 | 17 | NO | NO |
CVE-2023-44075MEDIUM Cross Site Scripting vulnerability in Small CRM in PHP v.3.0 allows a remote attacker to execute arbitrary code via a crafted payload to the Address parameter. | Oct 4, 2023 | 5.4 | 17 | NO | NO |
CVE-2023-43331MEDIUM A cross-site scripting (XSS) vulnerability in the Add User function of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into | Sep 27, 2023 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Small Crm Project.
Media articles that mention a CVE ID that affects a product developed by Small Crm Project — matched by CVE ID, not by vendor name.