Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.32% | — | Codecanyon Perfex CRMAI | 5/5/2026 | 17/6/2026 | A flaw has been found in CodeCanyon Perfex CRM up to 3.4.1. This vulnerability affects the function AbstractKanban::applySortQuery of the file application/services/AbstractKanban.php of the component Admin Kanban Endpoint. This manipulation of the argument this causes sql injection. It is possible to initiate the… | |
| Aplazada | Baja (2.1) | 0.36% | — | Codecanyon Perfex CRMAI | 4/5/2026 | 17/6/2026 | A vulnerability was detected in CodeCanyon Perfex CRM up to 3.4.1. This affects the function Clients::project of the file application/controllers/Clients.php of the component Tenant Handler. The manipulation of the argument ID results in authorization bypass. The attack may be performed from remote. The exploit is now… | |
| Aplazada | Media (6.1) | 0.34% | — | Perfexcrm Perfex CRMAI | 14/10/2025 | 17/6/2026 | Stored Cross-Site Scripting (XSS) in Perfex CRM chatbot before 3.3.1 allows attackers to inject arbitrary HTML/JavaScript. The payload is executed in the browsers of users viewing the chat, resulting in client-side code execution, potential session token theft, and other malicious actions. A different vulnerability… | |
| Aplazada | Alta (8.3) | 0.34% | — | Perfex CRMAI | 10/10/2025 | 17/6/2026 | A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate module. As a result, arbitrary HTML can be injected and rendered unescaped in client-facing documents. | |
| Aplazada | Alta (7.3) | 0.28% | — | Perfex CRMAI | 9/10/2025 | 17/6/2026 | The authentication mechanism in Perfex CRM before 3.3.1 allows attackers to bypass login credentials due to insufficient server-side validation. By sending empty username and password parameters in the login request, an attacker can gain unauthorized access to user accounts, including administrative accounts, without… | |
| Analizada | Media (5.3) | 0.19% | — | Perfexcrm Perfex CRM | 29/9/2025 | 17/6/2026 | HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a POST request in the parameters 'subject' at the endpoint 'knoewledge_base/article'. | |
| Analizada | Media (5.3) | 0.24% | — | Perfexcrm Perfex CRM | 29/9/2025 | 17/6/2026 | HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a POST request in the parameters 'name' and 'address' at the endpoint 'admin/leads/lead'. | |
| Analizada | Media (5.3) | 0.24% | — | Perfexcrm Perfex CRM | 29/9/2025 | 17/6/2026 | HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a POST request in the parameters 'name' and 'clientid' at the endpoint '/projects/project/x'. | |
| Analizada | Media (5.3) | 0.24% | — | Perfexcrm Perfex CRM | 29/9/2025 | 17/6/2026 | HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a POST request in the parameter 'expense_name' at the endpoint '/expenses/expense'. | |
| Analizada | Media (5.3) | 0.24% | — | Perfexcrm Perfex CRM | 29/9/2025 | 17/6/2026 | HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a POST request in the parameter 'name' at the endpoint '/subscriptions/create'. | |
| Analizada | Media (5.3) | 0.24% | — | Perfexcrm Perfex CRM | 29/9/2025 | 17/6/2026 | HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a POST request in the parameter 'company' at the endpoint '/clients/client/x. | |
| Analizada | Media (5.1) | 0.38% | — | Perfexcrm Perfex CRM | 4/4/2025 | 17/6/2026 | A vulnerability was found in CodeCanyon Perfex CRM 3.2.1. It has been classified as problematic. Affected is an unknown function of the file /perfex/clients/project/2 of the component Project Discussions Module. The manipulation of the argument description leads to cross site scripting. It is possible to launch the… | |
| Analizada | Media (5.1) | 0.37% | — | Perfexcrm Perfex CRM | 31/3/2025 | 17/6/2026 | A vulnerability has been found in CodeCanyon Perfex CRM up to 3.2.1 and classified as problematic. This vulnerability affects unknown code of the file /contract of the component Contracts. The manipulation of the argument content leads to cross site scripting. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Media (6.8) | 0.63% | — | Perfexcrm Perfex CRMAI | 13/2/2025 | 17/6/2026 | In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file endpoint. By providing malicious input in the rel_id parameter, combined with improper input validation, the attacker can bypass restrictions and upload arbitrary files to directories of their… | |
| Analizada | Media (5.3) | 0.48% | — | Perfexcrm Perfex CRM | 15/9/2024 | 17/6/2026 | A vulnerability was found in Perfex CRM 3.1.6. It has been declared as problematic. This vulnerability affects unknown code of the file application/controllers/Clients.php of the component Parameter Handler. The manipulation of the argument message leads to cross site scripting. The attack can be initiated remotely.… | |
| Analizada | Media (5.4) | 0.40% | — | Perfexcrm Perfex CRM | 11/9/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Discussion section of Perfex CRM v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Content parameter. | |
| Modificada | Media (5.4) | 0.53% | — | Perfexcrm Perfex CRM | 8/11/2022 | 17/6/2026 | perfex crm 1.10 is vulnerable to Cross Site Scripting (XSS) via /clients/profile. | |
| Modificada | Media (5.4) | 0.58% | — | Perfexcrm Perfex CRM | 22/10/2021 | 17/6/2026 | Perfex CRM v2.4.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component ./clients/client via the company name parameter. | |
| Modificada | Crítica (9.8) | 13% | — | Perfexcrm Perfex CRM | 26/1/2018 | 17/6/2026 | In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution. |