X2engine

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 15
    Known Exploited: 0
    0
    Critical Level Threats
    4
    High Level Threats
    11
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-48120

    X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject malicious JavaScript code into the "Name" field when creating a list.

    Last Modified: Oct 29, 2024
    Published: Oct 14, 2024

    CVE-2022-48178

    X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action function, aka an index.php/actions/update URI.

    Last Modified: Jan 30, 2026
    Published: Apr 15, 2023

    CVE-2022-48177

    X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importModels Import Records Model field (model parameter). This vulnerability allows attackers to create malicious JavaScript that will be executed by the victim user's browser.

    Last Modified: Jan 30, 2026
    Published: Apr 15, 2023

    CVE-2021-33853

    A Cross-Site Scripting (XSS) attack can cause arbitrary code (javascript) to run in a user’s browser while the browser is connected to a trusted website. As the vehicle for the attack, the application targets the users and not the application itself. Additionally, the XSS payload is executed when the user attempts to access any page of the CRM.

    Last Modified: Nov 21, 2024
    Published: Mar 16, 2022

    CVE-2020-21088

    Cross Site Scripting (XSS) in X2engine X2CRM v7.1 and older allows remote attackers to obtain sensitive information by injecting arbitrary web script or HTML via the "First Name" and "Last Name" fields in "/index.php/contacts/create page"

    Last Modified: Nov 21, 2024
    Published: Apr 14, 2021
    Items Per Page
    X2engine Vulnerabilities & Security CVEs | CVE-DB