Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY24 SECURITY RECORDS

espocrm

espocrm

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-92298 16 Sep 2026 EspoCRM: ≤ 10.0.8 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-90934 14 Sep 2026 espocrm: < 10.0.4 espocrm: 10.0.4 Update reference ↗
CVE-2026-88896 10 Sep 2026 espocrm: < 10.0.4 espocrm: 10.0.4 Update reference ↗
CVE-2026-41141 28 May 2026 < 9.3.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-41160 28 May 2026 < 9.3.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-33741 19 May 2026 < 9.3.4 9.3.4. Update reference ↗
CVE-2026-33733 22 Apr 2026 < 9.3.4 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2026-33656 22 Apr 2026 < 9.3.4 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-33740 13 Apr 2026 < 9.3.4 9.3.4. Update reference ↗
CVE-2026-33659 13 Apr 2026 < 9.3.4 9.3.4. Update reference ↗
CVE-2026-33657 13 Apr 2026 < 9.3.4 9.3.4. Update reference ↗
CVE-2026-33534 13 Apr 2026 < 9.3.4 9.3.4. Update reference ↗
CVE-2020-37094 3 Feb 2026 5.7.0 < 5.9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-59428 14 Oct 2025 < 9.1.9 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2025-52892 5 Aug 2025 < 9.1.7 9.1.7. Update reference ↗
CVE-2025-52575 21 Jul 2025 < 9.1.7 9.1.7. Update reference ↗
CVE-2025-32390 12 May 2025 < 9.0.8 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-32789 16 Apr 2025 < 9.0.7 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-32385 15 Apr 2025 < 9.0.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-24818 29 Feb 2024 < 8.1.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-46736 5 Dec 2023 < 8.0.5 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-5966 30 Nov 2023 ≤ 7.5.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-5965 30 Nov 2023 ≤ 7.5.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2021-3539 4 Aug 2021 6.1.6 ≤ 6.1.6 6.1.7 Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.