VYPR

Energy CRM

by Status Tracker Ltd

CVEs (2)

  • CVE-2025-40643MedOct 23, 2025
    risk 0.35cvss 5.4epss 0.00

    Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS due to lack of proper validation of user input by sending a POST request to “/crm/create_job_submit.php”, using the “JobCreatedBy” parameter. This…

  • CVE-2025-40640MedOct 10, 2025
    risk 0.35cvss 5.4epss 0.00

    Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS due to lack of proper validation of user input by sending a POST request to “/crm/create_invoice_submit.php”, using the “customerName_0” parameter. This…