Perfexcrm

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 15
    Known Exploited: 0
    1
    Critical Level Threats
    1
    High Level Threats
    10
    Medium Level Threats
    3
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-60374

    Stored Cross-Site Scripting (XSS) in Perfex CRM chatbot before 3.3.1 allows attackers to inject arbitrary HTML/JavaScript. The payload is executed in the browsers of users viewing the chat, resulting in client-side code execution, potential session token theft, and other malicious actions. A different vulnerability than CVE-2024-8867.

    Last Modified: Apr 15, 2026
    Published: Oct 14, 2025

    CVE-2025-60375

    The authentication mechanism in Perfex CRM before 3.3.1 allows attackers to bypass login credentials due to insufficient server-side validation. By sending empty username and password parameters in the login request, an attacker can gain unauthorized access to user accounts, including administrative accounts, without providing valid credentials.

    Last Modified: Apr 15, 2026
    Published: Oct 09, 2025

    CVE-2025-10346

    HTML injection in Perfex CRM

    Last Modified: Oct 02, 2025
    Published: Sep 29, 2025

    CVE-2025-10345

    HTML injection in Perfex CRM

    Last Modified: Oct 02, 2025
    Published: Sep 29, 2025

    CVE-2025-10344

    HTML injection in Perfex CRM

    Last Modified: Oct 02, 2025
    Published: Sep 29, 2025
    Items Per Page
    Perfexcrm Vulnerabilities & Security CVEs | CVE-DB