PatchSiren

EspoCRM CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM espocrm CVE published 2026-10-08

CVE-2026-105832

CVE-2026-105832 debrief: EspoCRM before 10.0.6 contains an authentication bypass vulnerability on unauthenticated routes, allowing attackers to bypass two-factor authentication. Defenders should assess exposure and prioritize verification and remediation. The vulnerability has a medium severity and affects EspoCRM deployments. Verify authentication configurations and two-factor authentication settings to [truncated]

MEDIUM espocrm CVE published 2026-10-08

CVE-2026-105831

CVE-2026-105831 debrief: EspoCRM before 10.0.6 Unauthenticated Stored HTML Injection via Lead Capture Form. The vulnerability allows unauthenticated attackers to inject HTML by submitting crafted Lead Capture public form data, which is stored in LeadCaptureLogRecord.data and rendered unescaped when administrators view the log record. Defenders should assess exposure and potential impact, particularly thos [truncated]

MEDIUM EspoCRM CVE published 2026-09-16

CVE-2026-92298

CVE-2026-92298 is a vulnerability in EspoCRM versions up to 10.0.8, where the application uses PHP's rand() function to generate tokens, which can be guessed by remote unauthenticated attackers. This allows them to confirm opt-ins, accept or decline event invitations on behalf of other contacts, and access event details. The vulnerability has a medium severity and defenders should assess exposure and veri [truncated]

HIGH espocrm CVE published 2026-09-14

CVE-2026-90934

CVE-2026-90934 is a field-level security bypass vulnerability in EspoCRM before 10.0.4, allowing authenticated users to read restricted email addresses of meeting and call attendees. The vulnerability is caused by incorrect ACL scope validation that checks parent event permissions instead of attendee entity permissions. This issue may lead to unintended data exposure in sensitive deployments. Defenders sh [truncated]

MEDIUM espocrm CVE published 2026-09-10

CVE-2026-88896

CVE-2026-88896 is a server-side request forgery vulnerability in EspoCRM before version 10.0.4. The vulnerability allows an attacker to bypass internal-host validation and CURLOPT_RESOLVE IP-pinning checks by using IPv6 transition addresses, causing EspoCRM to issue outbound requests to internal network services. This could lead to unauthorized access to internal network services, potentially resulting in [truncated]

MEDIUM espocrm CVE published 2026-05-28

CVE-2026-41160

A broken access control vulnerability in EspoCRM 9.3.3 allows low-privileged users to persistently modify note pinning status without proper authorization. The flaw exists in the POST /api/v1/Note/{id}/pin endpoint where the server processes the write operation before validating permissions, resulting in a 'write first, authorize later' execution pattern. While the API returns a 403 Forbidden response, th [truncated]

MEDIUM espocrm CVE published 2026-05-28

CVE-2026-41141

EspoCRM versions prior to 9.3.5 contain an authorization bypass vulnerability in the email template preparation endpoint. The POST /api/v1/EmailTemplate/:id/prepare endpoint accepts an emailAddress parameter to resolve the owning entity (Contact, Lead, Account, or User) without performing an access control list (ACL) check. An authenticated attacker with EmailTemplate read permission can extract all field [truncated]

MEDIUM espocrm CVE published 2026-05-19

CVE-2026-33741

CVE-2026-33741 affects EspoCRM versions 9.3.3 and below. The issue stems from SVG attachments being uploadable through normal attachment-capable fields and then rendered as top-level inline content through attachment and image entry points. That creates a stored cross-user XSS condition reachable through an ordinary workflow. The response CSP blocks inline SVG script, but the same-origin external script a [truncated]

HIGH EspoCRM CVE published 2026-02-03

CVE-2020-37094

CVE-2020-37094 details an authentication token reuse vulnerability in EspoCRM 5.7.0 prior to 5.9.0. This vulnerability allows authenticated attackers to bypass two-factor authentication by exploiting token-to-password-hash mapping. Attackers can obtain an authentication token for a controlled account and replay it against any victim account sharing the same password, bypassing the victim's 2FA protections [truncated]