Zurmo develops a customer relationship management platform whose vulnerability profile centers on a narrow product scope but maintains notable prominence within the CRM and business-application landscape. The recurring exposures reflect characteristic weaknesses of web-facing applications: cross-site scripting and open-redirect flaws that arise from improper input handling and URL validation in the platform's request and navigation logic. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zurmo over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16654MEDIUM Zurmo 3.2.4 Stable allows XSS via app/index.php/accounts/default/details?id=2&kanbanBoard=1&openToTaskId=1. | Sep 7, 2018 | 6.1 | 22 | NO | NO |
CVE-2019-14472MEDIUM Zurmo 3.2.7-2 has XSS via the app/index.php/zurmo/default PATH_INFO. | Aug 1, 2019 | 6.1 | 20 | NO | NO |
CVE-2018-19506MEDIUM Zurmo 3.2.4 has XSS via an admin's use of the name parameter in the reports section, aka the app/index.php/reports/default/details?id=1 URI. | Dec 19, 2018 | 4.8 | 19 | NO | NO |
CVE-2017-18004MEDIUM Zurmo 3.2.3 allows XSS via the latitude or longitude parameter to maps/default/mapAndPoint. | Dec 31, 2017 | 5.4 | 19 | NO | NO |
CVE-2017-16569MEDIUM An Open URL Redirect issue exists in Zurmo 3.2.1.57987acc3018 via an http: URL in the redirectUrl parameter to app/index.php/meetings/default/createMeeting. | Nov 6, 2017 | 4.8 | 19 | NO | NO |
CVE-2017-15039MEDIUM Cross-site scripting (XSS) exists in Zurmo 3.2.1.57987acc3018 via a data: URL in the redirectUrl parameter to app/index.php/meetings/default/createMeeting. | Nov 6, 2017 | 4.8 | 19 | NO | NO |
CVE-2018-19596MEDIUM Zurmo 3.2.4 allows HTML Injection via an admin's use of HTML in the report section, a related issue to CVE-2018-19506. | Dec 19, 2018 | 4.8 | 18 | NO | NO |
CVE-2017-7188MEDIUM Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl parameter to default/toggleCollapse. | Apr 14, 2017 | 5.4 | 16 | NO | NO |
Cross-site scripting (XSS) vulnerability in Zurmo CRM 3.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "What's going on?" profile field. | Jul 2, 2015 | 3.5 | 13 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zurmo.
Media articles that mention a CVE ID that affects a product developed by Zurmo — matched by CVE ID, not by vendor name.