VYPR
Vendor

Defaultfuction

Products
4
CVEs
8
Across products
9
Status
Private

Products

4

Recent CVEs

8
  • CVE-2026-5333HigApr 2, 2026
    risk 0.48cvss 7.3epss 0.04

    A security flaw has been discovered in DefaultFuction Content-Management-System 1.0. This issue affects some unknown processing of the file /admin/tools.php. The manipulation of the argument host results in command injection. The attack can be executed remotely. The exploit has…

  • CVE-2026-86172MedSep 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public…

  • CVE-2026-86171MedSep 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed…

  • CVE-2026-86170MedSep 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made…

  • CVE-2026-19933MedAug 16, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in DefaultFuction Customer-Relationship-Management-In-C-Project 2.0. Impacted is the function gets of the component Customer Search Module. This manipulation causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has…

  • CVE-2026-19932MedAug 16, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in DefaultFuction Notice-System-Managent 2.0. This issue affects the function GroovyShell.evaluate of the file /execute of the component NoticeController. The manipulation results in code injection. The attack can be launched remotely. The…

  • CVE-2026-3616MedMar 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in DefaultFuction Jeson Customer Relationship Management System 1.0.0. Impacted is an unknown function of the file /modules/customers/edit.php. Performing a manipulation of the argument ID results in sql injection. The attack may be initiated…

  • CVE-2026-4623HigMar 24, 2026
    risk 0.40cvss 7.3epss 0.01

    A security vulnerability has been detected in DefaultFuction Jeson-Customer-Relationship-Management-System up to 1b4679c4d06b90d31dd521c2b000bfdec5a36e00. This affects an unknown function of the file /api/System.php of the component API Module. The manipulation of the argument…