Vendors5kcrmwukong_crmall versions
Vulnerabilities

5kcrm Wukong

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2024-23052
An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.
Published 2024-02-01 · Analyzed
9.8EPSS 0.049
CVE-2026-2141
WuKongOpenSource WukongCRM URL PermissionServiceImpl.java improper authorization
Published 2026-02-08 · Analyzed
8.8EPSS 0.004
CVE-2025-5521
WuKongOpenSource WukongCRM updataPassword cross-site request forgery
Published 2025-06-03 · Analyzed
8.8EPSS 0.003
CVE-2025-60828
WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine interface.
Published 2025-10-08 · Analyzed
6.5EPSS 0.004
CVE-2025-8852
WuKongOpenSource WukongCRM API Response upload information exposure
Published 2025-08-11 · Analyzed
4.3EPSS 0.004