VYPR
Vendor

Crmeb

Products
2
CVEs
46
Across products
48
Status
Private

Products

2

Recent CVEs

46
View all 46 CVEs →
  • CVE-2025-25763CriMar 6, 2025
    risk 0.64cvss 9.8epss 0.01

    crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php

  • CVE-2023-30185CriMay 8, 2023
    risk 0.64cvss 9.8epss 0.01

    CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.

  • CVE-2020-21787CriJun 24, 2021
    risk 0.64cvss 9.8epss 0.02

    CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.

  • CVE-2020-25466CriOct 23, 2020
    risk 0.64cvss 9.8epss 0.03

    A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.

  • CVE-2020-21394HigJun 29, 2021
    risk 0.57cvss 8.8epss 0.01

    SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename parameter in SystemDatabackup.php.

  • CVE-2026-79425HigSep 15, 2026
    risk 0.53cvss 8.1epss 0.00

    An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of CRMEB v6.0.0 allows attackers to scan internal resources via a crafted POST request.

  • CVE-2024-52726HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.02

    CRMEB v5.4.0 is vulnerable to Arbitrary file read in the save_basics function which allows an attacker to obtain sensitive information

  • CVE-2024-50653HigNov 15, 2024
    risk 0.49cvss 7.5epss 0.01

    CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able to claim coupons once by capturing packets and sending a large number of data packets for coupon collection, achieving unlimited coupon collection.

  • CVE-2024-36837HigJun 5, 2024
    risk 0.49cvss 7.5epss 0.08

    SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.

  • CVE-2024-25469HigFeb 23, 2024
    risk 0.49cvss 7.5epss 0.01

    SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitude and longitude parameters in the api/front/store/list component.

  • CVE-2022-44343HigFeb 6, 2023
    risk 0.49cvss 7.5epss 0.01

    CRMEB 4.4.4 is vulnerable to Any File download.

  • CVE-2026-1202HigJan 20, 2026
    risk 0.48cvss 7.3epss 0.01

    A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file crmeb/app/api/controller/v1/LoginController.php. Performing a manipulation of the argument openId results in improper authentication. The attack is possible to…

  • CVE-2026-79426HigSep 4, 2026
    risk 0.47cvss 7.2epss 0.00

    An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via crafted POST request.

  • CVE-2026-85212HigSep 3, 2026
    risk 0.47cvss 8.3epss 0.00

    CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrators and accounts with no roles can access restricted admin endpoints by exploiting the inert role check…

  • CVE-2026-10771HigJun 3, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zbkj/common/utils/RestTemplateUtil.java of the component base64 Qrcode Endpoint. The manipulation of the argument url results in…

  • CVE-2023-25223HigMar 7, 2023
    risk 0.47cvss 7.2epss 0.01

    CRMEB <=1.3.4 is vulnerable to SQL Injection via /api/admin/user/list.

  • CVE-2024-28714HigMar 28, 2024
    risk 0.46cvss 8.1epss 0.01

    SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter.

  • CVE-2024-24110MedMar 21, 2024
    risk 0.42cvss 6.5epss 0.01

    SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET request to the component /api/front/spread/people.

  • CVE-2025-11288MedOct 5, 2025
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in CRMEB up to 5.6. This issue affects some unknown processing of the file /adminapi/product/product of the component GET Parameter Handler. Performing a manipulation of the argument cate_id results in sql injection. Remote exploitation of the…

  • CVE-2025-10391MedSep 14, 2025
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in CRMEB up to 5.6.1. The impacted element is the function testOutUrl of the file app/services/out/OutAccountServices.php. The manipulation of the argument push_token_url leads to server-side request forgery. Remote exploitation of the…