Skip to main content

Vendor/product archive

x2engine / x2crm CVEs

Beta · best-effort

13 CVEs tagged to x2engine / x2crm0 Critical, 3 High, 10 Medium, 0 Low, 0 Unrated.

CVE-2024-48120

Published Oct 14, 2024

X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject malicious JavaScript code into the "Name" field when creating…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-48178

Published Apr 15, 2023

X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action function, aka an index.php/actions/update…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-48177

Published Apr 15, 2023

X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importModels Import Records Model field (model…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-33853

Published Mar 16, 2022

A Cross-Site Scripting (XSS) attack can cause arbitrary code (javascript) to run in a user’s browser while the browser is connected to a trusted website. As the vehicle for the at…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27288

Published Apr 14, 2021

Cross Site Scripting (XSS) in X2Engine X2CRM v7.1 allows remote attackers to obtain sensitive information by injecting arbitrary web script or HTML via the "Comment" field in "/pr…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-21088

Published Apr 14, 2021

Cross Site Scripting (XSS) in X2engine X2CRM v7.1 and older allows remote attackers to obtain sensitive information by injecting arbitrary web script or HTML via the "First Name"…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-21087

Published Apr 14, 2021

Cross Site Scripting (XSS) in X2Engine X2CRM v6.9 and older allows remote attackers to execute arbitrary code by injecting arbitrary web script or HTML via the "New Name" field of…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2664

Published Oct 17, 2017

Unrestricted file upload vulnerability in the ProfileController::actionUploadPhoto method in protected/controllers/ProfileController.php in X2Engine X2CRM before 4.0 allows remote…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5076

Published Sep 29, 2015

Multiple cross-site scripting (XSS) vulnerabilities in X2Engine X2CRM before 5.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) version parameter in p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5075

Published Sep 29, 2015

Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authentication of administrators for requests that create an adm…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5074

Published Sep 29, 2015

Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php in X2Engine X2CRM before 5.0.9 allows remote authenticated…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5693

Published Sep 30, 2013

Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web script or HTML via the model parameter to index.php/admin/edi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5692

Published Sep 30, 2013

Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the fi…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1