Crmeb
Crmeb Java: vulnerabilidades y CVE
Crmeb Java tiene 10 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses2
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-10771 | Media (5.5) | 0.29% | — | 3 jun 2026 | A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zbkj/common/utils/RestTemplateUtil.java of the component base64 Qrcode… |
| CVE-2026-7673 | Baja (2) | 0.38% | — | 3 may 2026 | A vulnerability was detected in crmeb_java up to 1.3.4. This vulnerability affects unknown code of the file crmeb/crmeb-service/src/main/java/com/zbkj/service/service/impl/UploadServiceImpl.java of the component Admin… |
| CVE-2025-2365 | Media (5.3) | 0.36% | — | 17 mar 2025 | A vulnerability, which was classified as problematic, has been found in crmeb_java up to 1.3.4. Affected by this issue is the function webHook of the file WeChatMessageController.java. The manipulation leads to xml… |
| CVE-2024-33117 | Media (5.3) | 0.47% | — | 6 may 2024 | crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeController. |
| CVE-2024-28714 | Alta (8.1) | 0.85% | — | 28 mar 2024 | SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter. |
| CVE-2024-24110 | Media (6.5) | 0.61% | — | 21 mar 2024 | SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET request to the component /api/front/spread/people. |
| CVE-2024-25469 | Alta (7.5) | 0.79% | — | 23 feb 2024 | SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitude and longitude parameters in the api/front/store/list component. |
| CVE-2023-1609 | Media (5.4) | 0.52% | — | 23 mar 2023 | A vulnerability was found in Zhong Bang CRMEB Java up to 1.3.4. It has been rated as problematic. This issue affects the function save of the file /api/admin/store/product/save. The manipulation leads to cross site… |
| CVE-2023-1608 | Crítica (9.8) | 0.63% | — | 23 mar 2023 | A vulnerability was found in Zhong Bang CRMEB Java up to 1.3.4. It has been declared as critical. This vulnerability affects the function getAdminList of the file /api/admin/store/product/list. The manipulation of the… |
| CVE-2023-25223 | Alta (7.2) | 0.76% | — | 7 mar 2023 | CRMEB <=1.3.4 is vulnerable to SQL Injection via /api/admin/user/list. |