{"api_version":"v1","generated_at":"2026-10-07T14:15:00+00:00","product":{"cve_count":19,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-espocrm-espocrm-44d056815d95","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"espocrm","next_cursor":null,"observations":[{"affected":"EspoCRM: \u2264 10.0.8","affected_versions_present":true,"cve_id":"CVE-2026-92298","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-92298","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-17T17:04:28.939Z","patch_url":"","primary_source":"","published":"2026-09-16T01:57:46.309Z"},{"affected":"espocrm: < 10.0.4","affected_versions_present":true,"cve_id":"CVE-2026-90934","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90934","fixed":"espocrm: 10.0.4","last_modified":"2026-09-14T18:12:16.603Z","patch_url":"https://github.com/espocrm/espocrm/security/advisories/GHSA-hpgx-8qg3-5w7v","primary_source":"","published":"2026-09-14T12:48:29.191Z"},{"affected":"espocrm: < 10.0.4","affected_versions_present":true,"cve_id":"CVE-2026-88896","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-88896","fixed":"espocrm: 10.0.4","last_modified":"2026-09-15T14:29:20.008Z","patch_url":"https://github.com/espocrm/espocrm/security/advisories/GHSA-xwmh-j8hf-cfqw","primary_source":"","published":"2026-09-10T13:05:43.054Z"},{"affected":"< 9.3.5","affected_versions_present":true,"cve_id":"CVE-2026-41141","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41141","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-28T18:54:06.117Z","patch_url":"","primary_source":"","published":"2026-05-28T16:25:03.256Z"},{"affected":"< 9.3.5","affected_versions_present":true,"cve_id":"CVE-2026-41160","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41160","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-28T19:04:24.739Z","patch_url":"","primary_source":"","published":"2026-05-28T16:24:19.970Z"},{"affected":"< 9.3.4","affected_versions_present":true,"cve_id":"CVE-2026-33741","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33741","fixed":"9.3.4.","last_modified":"2026-05-20T14:02:11.490Z","patch_url":"https://github.com/espocrm/espocrm/security/advisories/GHSA-5wh5-ccv2-m3pv","primary_source":"","published":"2026-05-19T18:14:36.157Z"},{"affected":"< 9.3.4","affected_versions_present":true,"cve_id":"CVE-2026-33733","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33733","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-23T16:25:04.022Z","patch_url":"https://github.com/espocrm/espocrm/security/advisories/GHSA-44c3-xjfp-3jrh","primary_source":"","published":"2026-04-22T20:05:23.809Z"},{"affected":"< 9.3.4","affected_versions_present":true,"cve_id":"CVE-2026-33656","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33656","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-23T13:47:56.303Z","patch_url":"","primary_source":"","published":"2026-04-22T20:01:24.195Z"},{"affected":"< 9.3.4","affected_versions_present":true,"cve_id":"CVE-2026-33740","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33740","fixed":"9.3.4.","last_modified":"2026-04-14T15:50:45.744Z","patch_url":"https://github.com/espocrm/espocrm/commit/88e3ba6a7b5cab5dbc2298e2a093d3aa383aa95f","primary_source":"","published":"2026-04-13T20:37:28.831Z"},{"affected":"< 9.3.4","affected_versions_present":true,"cve_id":"CVE-2026-33659","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33659","fixed":"9.3.4.","last_modified":"2026-04-14T13:52:31.103Z","patch_url":"https://github.com/espocrm/espocrm/commit/dca03cc3458e487362c26c746378a2d4de9990b1","primary_source":"","published":"2026-04-13T20:32:07.072Z"},{"affected":"< 9.3.4","affected_versions_present":true,"cve_id":"CVE-2026-33657","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33657","fixed":"9.3.4.","last_modified":"2026-04-13T20:48:47.307Z","patch_url":"https://github.com/espocrm/espocrm/security/advisories/GHSA-8prm-r5j9-j574","primary_source":"","published":"2026-04-13T19:41:47.131Z"},{"affected":"< 9.3.4","affected_versions_present":true,"cve_id":"CVE-2026-33534","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33534","fixed":"9.3.4.","last_modified":"2026-04-14T16:28:58.299Z","patch_url":"https://github.com/espocrm/espocrm/security/advisories/GHSA-h7gx-8gwv-7g73","primary_source":"","published":"2026-04-13T19:20:04.414Z"},{"affected":"5.7.0 < 5.9.0","affected_versions_present":true,"cve_id":"CVE-2020-37094","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-37094","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T01:24:24.326Z","patch_url":"","primary_source":"","published":"2026-02-03T22:01:52.861Z"},{"affected":"< 9.1.9","affected_versions_present":true,"cve_id":"CVE-2025-59428","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59428","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-10-14T16:03:42.715Z","patch_url":"https://github.com/espocrm/espocrm/security/advisories/GHSA-c26c-wvhr-fr6r","primary_source":"","published":"2025-10-14T14:38:20.090Z"},{"affected":"< 9.1.7","affected_versions_present":true,"cve_id":"CVE-2025-52892","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-52892","fixed":"9.1.7.","last_modified":"2025-08-05T13:48:45.234Z","patch_url":"https://github.com/espocrm/espocrm/commit/929611f317ce8892ea75873b0ab3094c0c510ff3","primary_source":"","published":"2025-08-05T00:17:16.047Z"},{"affected":"< 9.1.7","affected_versions_present":true,"cve_id":"CVE-2025-52575","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-52575","fixed":"9.1.7.","last_modified":"2025-07-21T18:09:07.329Z","patch_url":"https://github.com/espocrm/espocrm/commit/8649f1ac0ce714b2c31727bca3dd95d06e17337f","primary_source":"","published":"2025-07-21T17:48:11.466Z"},{"affected":"< 9.0.8","affected_versions_present":true,"cve_id":"CVE-2025-32390","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-32390","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-05-12T12:39:09.869Z","patch_url":"https://github.com/espocrm/espocrm/commit/6b58d30eec8864de52844bfb8dac346ce5c729d7","primary_source":"","published":"2025-05-12T10:30:52.179Z"},{"affected":"< 9.0.7","affected_versions_present":true,"cve_id":"CVE-2025-32789","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-32789","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-17T13:14:36.548Z","patch_url":"https://github.com/espocrm/espocrm/commit/91740192d2e2c575c6a04534c079baf9f3af0a7f","primary_source":"","published":"2025-04-16T21:45:21.625Z"},{"affected":"< 9.0.5","affected_versions_present":true,"cve_id":"CVE-2025-32385","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-32385","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-17T14:23:10.191Z","patch_url":"","primary_source":"","published":"2025-04-15T23:23:58.292Z"},{"affected":"< 8.1.2","affected_versions_present":true,"cve_id":"CVE-2024-24818","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-24818","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-05T17:15:03.682Z","patch_url":"https://github.com/espocrm/espocrm/commit/3babdfa3399e328fb1bd83a1b4ed03d509f4c8e7","primary_source":"","published":"2024-02-29T15:17:16.859Z"},{"affected":"< 8.0.5","affected_versions_present":true,"cve_id":"CVE-2023-46736","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-46736","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-02T20:53:21.184Z","patch_url":"https://github.com/espocrm/espocrm/commit/c536cee6375e2088f961af13db7aaa652c983072","primary_source":"","published":"2023-12-05T20:55:42.156Z"},{"affected":"\u2264 7.5.2","affected_versions_present":true,"cve_id":"CVE-2023-5966","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-5966","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-20T07:57:21.961Z","patch_url":"","primary_source":"","published":"2023-11-30T13:26:48.245Z"},{"affected":"\u2264 7.5.2","affected_versions_present":true,"cve_id":"CVE-2023-5965","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-5965","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-20T08:00:54.382Z","patch_url":"","primary_source":"","published":"2023-11-30T13:26:15.451Z"},{"affected":"6.1.6 \u2264 6.1.6","affected_versions_present":true,"cve_id":"CVE-2021-3539","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-3539","fixed":"6.1.7","last_modified":"2024-09-16T18:39:36.342Z","patch_url":"https://www.rapid7.com/blog/post/2021/07/27/multiple-open-source-web-app-vulnerabilities-fixed/","primary_source":"","published":"2021-08-04T22:20:47.939Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"espocrm"}}
