VendorsDaybydaycrmdaybydayall versions
Vulnerabilities

Daybydaycrm Daybyday

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2022-22113
DayByDay CRM - Insufficient Session Expiration after Password Change
Published 2022-01-13 · Modified
8.8EPSS 0.010
CVE-2022-22112
DayByDay CRM - Application-Wide Client-Side Template Injection (CSTI)
Published 2022-01-13 · Modified
5.4EPSS 0.006
CVE-2020-35704
Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Lead screen.
Published 2020-12-25 · Modified
5.4EPSS 0.006
CVE-2020-35705
Daybyday 2.1.0 allows stored XSS via the Name parameter to the New User screen.
Published 2020-12-25 · Modified
5.4EPSS 0.006
CVE-2020-35706
Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Project screen.
Published 2020-12-25 · Modified
5.4EPSS 0.006
CVE-2020-35707
Daybyday 2.1.0 allows stored XSS via the Company Name parameter to the New Client screen.
Published 2020-12-25 · Modified
5.4EPSS 0.006