Vulnerabilities (CVE)

Filtered by vendor Perfexcrm Subscribe
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-40303 1 Perfexcrm 1 Perfex Crm 2023-12-10 N/A 5.4 MEDIUM
perfex crm 1.10 is vulnerable to Cross Site Scripting (XSS) via /clients/profile.
CVE-2020-28961 1 Perfexcrm 1 Perfex Crm 2023-12-10 3.5 LOW 5.4 MEDIUM
Perfex CRM v2.4.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component ./clients/client via the company name parameter.
CVE-2017-17976 1 Perfexcrm 1 Perfex Crm 2023-12-10 7.5 HIGH 9.8 CRITICAL
In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution.