Vendors72CRMwukong_crmall versions
Vulnerabilities

72CRM Wukong CRM

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2022-37181
72crm 9.0 has an Arbitrary file upload vulnerability.
Published 2022-08-24 · Modified
9.8EPSS 0.012
CVE-2022-46610
72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Published 2023-01-10 · Modified
8.8EPSS 0.181
CVE-2022-37178
An issue was discovered in 72crm 9.0. There is a SQL Injection vulnerability in View the task calendar.
Published 2022-08-24 · Modified
8.8EPSS 0.011
CVE-2025-5879
WuKongOpenSource WukongCRM File Upload AdminSysConfigController.java cross site scripting
Published 2025-06-09 · Analyzed
5.4EPSS 0.003
CVE-2025-6106
WuKongOpenSource WukongCRM AdminRoleController.java cross-site request forgery
Published 2025-06-16 · Analyzed
5.0EPSS 0.003