0
I Use This!
Activity Not Available
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2021-27288 BDSA-2021-0958 Medium Apr 14, 2021 Cross Site Scripting (XSS) in X2Engine X2CRM v7.1 allows remote attackers to obtain sensitive information by injecting arbitrary web script or HTML via more...
7.1
CVE-2020-21088 BDSA-2018-5239 Low Apr 14, 2021 Cross Site Scripting (XSS) in X2engine X2CRM v7.1 and older allows remote attackers to obtain sensitive information by injecting arbitrary web script o more...
7.1, 6.9, 6.6, 6.5.2, 6.5.1, 6.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1
BDSA-2022-4194 Low Jul 11, 2023 X2CRM Open Source Sales CRM is vulnerable to reflected cross-site scripting (XSS) due to improper validation of user input supplied to the adin/importM more...
BDSA-2022-4193 Low Jul 11, 2023 X2CRM Open Source Sales CRM is vulnerable to stored cross-site scripting (XSS) due to improper validation of user supplied input. This could allow an a more...
BDSA-2021-4232 Low Mar 22, 2022 X2CRM is vulnerable to stored cross-site scripting (XSS) due to improper validation of user supplied input to the "Top Bar Link" field within the "User more...
BDSA-2018-5240 Low Apr 16, 2021 X2Engine X2CRM contains a cross-site scripting (XSS) vulnerability. An authenticated attacker can use this to execute malicious JavaScript code in a vi more...