VYPR

Crmeb

by Crmeb

Source repositories

CVEs (31)

  • CVE-2025-25763CriMar 6, 2025
    risk 0.64cvss 9.8epss 0.01

    crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php

  • CVE-2023-30185CriMay 8, 2023
    risk 0.64cvss 9.8epss 0.01

    CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.

  • CVE-2020-21787CriJun 24, 2021
    risk 0.64cvss 9.8epss 0.02

    CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.

  • CVE-2020-25466CriOct 23, 2020
    risk 0.64cvss 9.8epss 0.03

    A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.

  • CVE-2020-21394HigJun 29, 2021
    risk 0.57cvss 8.8epss 0.01

    SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename parameter in SystemDatabackup.php.

  • CVE-2024-52726HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.02

    CRMEB v5.4.0 is vulnerable to Arbitrary file read in the save_basics function which allows an attacker to obtain sensitive information

  • CVE-2024-50653HigNov 15, 2024
    risk 0.49cvss 7.5epss 0.01

    CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able to claim coupons once by capturing packets and sending a large number of data packets for coupon collection, achieving unlimited coupon collection.

  • CVE-2024-36837HigJun 5, 2024
    risk 0.49cvss 7.5epss 0.08

    SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.

  • CVE-2022-44343HigFeb 6, 2023
    risk 0.49cvss 7.5epss 0.01

    CRMEB 4.4.4 is vulnerable to Any File download.

  • CVE-2026-1202HigJan 20, 2026
    risk 0.48cvss 7.3epss 0.01

    A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file crmeb/app/api/controller/v1/LoginController.php. Performing a manipulation of the argument openId results in improper authentication. The attack is possible to…

  • CVE-2023-25223HigMar 7, 2023
    risk 0.47cvss 7.2epss 0.01

    CRMEB <=1.3.4 is vulnerable to SQL Injection via /api/admin/user/list.

  • CVE-2025-11288MedOct 5, 2025
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in CRMEB up to 5.6. This issue affects some unknown processing of the file /adminapi/product/product of the component GET Parameter Handler. Performing a manipulation of the argument cate_id results in sql injection. Remote exploitation of the…

  • CVE-2025-10391MedSep 14, 2025
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in CRMEB up to 5.6.1. The impacted element is the function testOutUrl of the file app/services/out/OutAccountServices.php. The manipulation of the argument push_token_url leads to server-side request forgery. Remote exploitation of the…

  • CVE-2024-6944MedJul 21, 2024
    risk 0.41cvss 6.3epss 0.04

    A vulnerability was found in ZhongBangKeJi CRMEB up to 5.4.0 and classified as critical. Affected by this issue is the function get_image_base64 of the file PublicController.php. The manipulation of the argument file leads to deserialization. The attack may be launched remotely.…

  • CVE-2024-6943MedJul 21, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability has been found in ZhongBangKeJi CRMEB up to 5.4.0 and classified as critical. Affected by this vulnerability is the function downloadImage of the file app/services/product/product/CopyTaobaoServices.php. The manipulation leads to deserialization. The attack can…

  • CVE-2023-3233MedJun 14, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Zhong Bang CRMEB up to 4.6.0. It has been classified as critical. Affected is the function get_image_base64 of the file api/controller/v1/PublicController.php. The manipulation leads to server-side request forgery. It is possible to launch the attack…

  • CVE-2023-3232MedJun 14, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Zhong Bang CRMEB up to 4.6.0 and classified as critical. This issue affects some unknown processing of the file /api/wechat/app_auth of the component Image Upload. The manipulation leads to deserialization. The exploit has been disclosed to the…

  • CVE-2026-1203MedJan 20, 2026
    risk 0.36cvss 5.6epss 0.01

    A weakness has been identified in CRMEB up to 5.6.3. The impacted element is the function remoteRegister of the file crmeb/app/services/user/LoginServices.php of the component JSON Token Handler. Executing a manipulation of the argument uid can lead to improper authentication.…

  • CVE-2025-11290MedOct 5, 2025
    risk 0.36cvss 5.6epss 0.00

    A vulnerability was identified in CRMEB up to 5.6.1. This affects an unknown function of the component JWT HMAC Secret Handler. Such manipulation of the argument secret with the input default leads to use of hard-coded cryptographic key . It is possible to launch the attack…

  • CVE-2024-1704MedFeb 21, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been declared as critical. This vulnerability affects the function save/delete of the file /adminapi/system/crud. The manipulation leads to path traversal. The exploit has been disclosed to the public and may be…

Page 1 of 2