Small Crm Smallcrmproject Small Crm

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Smallcrmproject Small Crm.

By the Year

In 2026 there have been 0 vulnerabilities in Smallcrmproject Small Crm. Small Crm did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 0 0.00
2024 0 0.00
2023 6 6.25
2022 0 0.00
2021 0 0.00
2020 1 8.80

It may take a day or so for new Small Crm vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Smallcrmproject Small Crm Security Vulnerabilities

PHPGurukul Small CRM 3.0: SQLI on Users Login Panel
CVE-2023-50035 9.8 - Critical - December 29, 2023

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is directly used in the SQL query without any sanitization and the SQL Injection payload being executed.

SQL Injection

SmallCRM v3.0 XSS in Company field Admin takeover
CVE-2023-45394 5.4 - Medium - October 20, 2023

Stored Cross-Site Scripting (XSS) vulnerability in the Company field in the "Request a Quote" Section of Small CRM v3.0 allows an attacker to store and execute malicious javascript code in the Admin panel which leads to Admin account takeover.

XSS

Small CRM v3.0 XSS in Address Param Allows Remote Code Execution
CVE-2023-44075 5.4 - Medium - October 04, 2023

Cross Site Scripting vulnerability in Small CRM in PHP v.3.0 allows a remote attacker to execute arbitrary code via a crafted payload to the Address parameter.

XSS

Cross-Site Scripting in Small CRM v3.0 Add User Name Field
CVE-2023-43331 5.4 - Medium - September 27, 2023

A cross-site scripting (XSS) vulnerability in the Add User function of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

XSS

XSS in PHPgurukl Small CRM v1.0
CVE-2023-34650 6.1 - Medium - June 28, 2023

PHPgurukl Small CRM v.1.0 is vulnerable to Cross Site Scripting (XSS).

XSS

XSS in Small CRM v3.0 Create Ticket Subject
CVE-2022-47073 5.4 - Medium - January 26, 2023

A cross-site scripting (XSS) vulnerability in the Create Ticket page of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Subject parameter.

XSS

PHPGurukul Small CRM v2.0 was found vulnerable to authentication bypass
CVE-2020-5511 8.8 - High - January 08, 2020

PHPGurukul Small CRM v2.0 was found vulnerable to authentication bypass via SQL injection when logging into the administrator login page.

SQL Injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Smallcrmproject Small Crm or by Smallcrmproject? Click the Watch button to subscribe.

subscribe