VYPR
Vendor

Crmeb

Products
2
CVEs
40
Across products
42
Status
Private

Products

2

Recent CVEs

40
View all 40 CVEs →
  • CVE-2025-25763CriMar 6, 2025
    risk 0.64cvss 9.8epss 0.01

    crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php

  • CVE-2023-30185CriMay 8, 2023
    risk 0.64cvss 9.8epss 0.01

    CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.

  • CVE-2020-21787CriJun 24, 2021
    risk 0.64cvss 9.8epss 0.02

    CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.

  • CVE-2020-25466CriOct 23, 2020
    risk 0.64cvss 9.8epss 0.03

    A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.

  • CVE-2020-21394HigJun 29, 2021
    risk 0.57cvss 8.8epss 0.01

    SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename parameter in SystemDatabackup.php.

  • CVE-2024-52726HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.02

    CRMEB v5.4.0 is vulnerable to Arbitrary file read in the save_basics function which allows an attacker to obtain sensitive information

  • CVE-2024-50653HigNov 15, 2024
    risk 0.49cvss 7.5epss 0.01

    CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able to claim coupons once by capturing packets and sending a large number of data packets for coupon collection, achieving unlimited coupon collection.

  • CVE-2024-36837HigJun 5, 2024
    risk 0.49cvss 7.5epss 0.08

    SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.

  • CVE-2024-25469HigFeb 23, 2024
    risk 0.49cvss 7.5epss 0.01

    SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitude and longitude parameters in the api/front/store/list component.

  • CVE-2022-44343HigFeb 6, 2023
    risk 0.49cvss 7.5epss 0.01

    CRMEB 4.4.4 is vulnerable to Any File download.

  • CVE-2026-1202HigJan 20, 2026
    risk 0.48cvss 7.3epss 0.01

    A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file crmeb/app/api/controller/v1/LoginController.php. Performing a manipulation of the argument openId results in improper authentication. The attack is possible to…

  • CVE-2026-10771HigJun 3, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zbkj/common/utils/RestTemplateUtil.java of the component base64 Qrcode Endpoint. The manipulation of the argument url results in…

  • CVE-2023-25223HigMar 7, 2023
    risk 0.47cvss 7.2epss 0.01

    CRMEB <=1.3.4 is vulnerable to SQL Injection via /api/admin/user/list.

  • CVE-2024-28714HigMar 28, 2024
    risk 0.46cvss 8.1epss 0.01

    SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter.

  • CVE-2024-24110MedMar 21, 2024
    risk 0.42cvss 6.5epss 0.01

    SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET request to the component /api/front/spread/people.

  • CVE-2025-11288MedOct 5, 2025
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in CRMEB up to 5.6. This issue affects some unknown processing of the file /adminapi/product/product of the component GET Parameter Handler. Performing a manipulation of the argument cate_id results in sql injection. Remote exploitation of the…

  • CVE-2025-10391MedSep 14, 2025
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in CRMEB up to 5.6.1. The impacted element is the function testOutUrl of the file app/services/out/OutAccountServices.php. The manipulation of the argument push_token_url leads to server-side request forgery. Remote exploitation of the…

  • CVE-2025-2365MedMar 17, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in crmeb_java up to 1.3.4. Affected by this issue is the function webHook of the file WeChatMessageController.java. The manipulation leads to xml external entity reference. The attack may be launched remotely.…

  • CVE-2024-6944MedJul 21, 2024
    risk 0.41cvss 6.3epss 0.04

    A vulnerability was found in ZhongBangKeJi CRMEB up to 5.4.0 and classified as critical. Affected by this issue is the function get_image_base64 of the file PublicController.php. The manipulation of the argument file leads to deserialization. The attack may be launched remotely.…

  • CVE-2024-6943MedJul 21, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability has been found in ZhongBangKeJi CRMEB up to 5.4.0 and classified as critical. Affected by this vulnerability is the function downloadImage of the file app/services/product/product/CopyTaobaoServices.php. The manipulation leads to deserialization. The attack can…