Vulnerabilities
37 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-1734 | A security flaw has been discovered in Zhong Bang CRMEB up to 5.6.3. A security flaw has been discovered in Zhong Bang CRMEB up to 5.6.3. This vulnerability affects unknown code of the file crmeb/app/api/controller/v1/CrontabController.php of the component crontab Endpoint. The manipulation results in missing authorization. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.5 | <1% | PoC ×2 |
| — | |
| CVE-2026-1733 | A vulnerability was identified in Zhong Bang CRMEB up to 5.6.3. A vulnerability was identified in Zhong Bang CRMEB up to 5.6.3. This affects the function detail/tidyOrder of the file /api/store_integral/order/detail/:uni. The manipulation of the argument order_id leads to improper authorization. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 2.1 | <1% | PoC ×2 |
| — | |
| CVE-2026-1202 +1 in the same advisory: …1203 | A security flaw has been discovered in CRMEB up to 5.6.3. A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file crmeb/app/api/controller/v1/LoginController.php. Performing a manipulation of the argument openId results in improper authentication. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.5 group max | <1% | PoC |
| — | |
| CVE-2025-15443 +1 in the same advisory: …15442 | A vulnerability was identified in CRMEB up to 5.6.1. A vulnerability was identified in CRMEB up to 5.6.1. This issue affects some unknown processing of the file /adminapi/product/product_export. Such manipulation of the argument cate_id leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 2.0 | <1% | PoC ×2 |
| — | |
| CVE-2025-11290 +1 in the same advisory: …11288 | A vulnerability was identified in CRMEB up to 5.6.1. A vulnerability was identified in CRMEB up to 5.6.1. This affects an unknown function of the component JWT HMAC Secret Handler. Such manipulation of the argument secret with the input default leads to use of hard-coded cryptographic key . It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is reported as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 2.9 group max | <1% |
| — | ||
| CVE-2025-10389 | A security flaw has been discovered in CRMEB up to 5.6.1. A security flaw has been discovered in CRMEB up to 5.6.1. Impacted is the function Save of the file app/services/system/admin/SystemAdminServices.php of the component Administrator Password Handler. Performing manipulation of the argument ID results in improper authorization. The attack may be initiated remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 2.1 | <1% |
| — | ||
| CVE-2025-25763 | crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2024-52726 | CRMEB v5.4.0 is vulnerable to Arbitrary file read in the save_basics function which allows an attacker to obtain sensitive information CRMEB v5.4.0 is vulnerable to Arbitrary file read in the save_basics function which allows an attacker to obtain sensitive information NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2024-50653 | CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able to claim coupons once by capturing packets and sending a large number of data packets for coupon collection, achieving unlimited coupon collection. NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2024-6944 +1 in the same advisory: …6943 | A vulnerability was found in ZhongBangKeJi CRMEB up to 5.4.0 and classified as critical. A vulnerability was found in ZhongBangKeJi CRMEB up to 5.4.0 and classified as critical. Affected by this issue is the function get_image_base64 of the file PublicController.php. The manipulation of the argument file leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-272066 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.3 | 4% |
| — | ||
| CVE-2024-36837 | SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.p SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file. NVD description · AI analysis pending | 7.5 | 8% |
| — | ||
| CVE-2024-33117 | crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeController. crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeController. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2024-28714 | SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter. SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter. NVD description · AI analysis pending | 8.1 | <1% | PoC ×2 |
| — | |
| CVE-2024-24110 | SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET request to the component /api/front/sprea SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET request to the component /api/front/spread/people. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2024-25469 | SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitude and longitude param SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitude and longitude parameters in the api/front/store/list component. NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2024-1704 +1 in the same advisory: …1703 | A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been declared as critical. This vulnerability affects the function save/delete of the file /adminapi/system/crud. The manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254392. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 8.1 group max | <1% | PoC |
| — | |
| CVE-2023-3232 | A vulnerability was found in Zhong Bang CRMEB up to 4.6.0 and classified as critical. A vulnerability was found in Zhong Bang CRMEB up to 4.6.0 and classified as critical. This issue affects some unknown processing of the file /api/wechat/app_auth of the component Image Upload. The manipulation leads to deserialization. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-231503. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — | |
| CVE-2023-30185 | CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php. CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2023-2419 | A vulnerability was found in Zhong Bang CRMEB 4.6.0. A vulnerability was found in Zhong Bang CRMEB 4.6.0. It has been declared as critical. This vulnerability affects the function videoUpload of the file \crmeb\app\services\system\attachment\SystemAttachmentServices.php. The manipulation of the argument filename leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-227716. NVD description · AI analysis pending | 7.2 | <1% | PoC |
| — | |
| CVE-2023-1608 +1 in the same advisory: …1609 | A vulnerability was found in Zhong Bang CRMEB Java up to 1.3.4. A vulnerability was found in Zhong Bang CRMEB Java up to 1.3.4. It has been declared as critical. This vulnerability affects the function getAdminList of the file /api/admin/store/product/list. The manipulation of the argument cateId leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-223738 is the identifier assigned to this vulnerability. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2023-25223 | CRMEB <=1.3.4 is vulnerable to SQL Injection via /api/admin/user/list. CRMEB <=1.3.4 is vulnerable to SQL Injection via /api/admin/user/list. NVD description · AI analysis pending | 7.2 | <1% | PoC |
| — | |
| CVE-2023-1165 | A vulnerability was found in Zhong Bang CRMEB Java 1.3.4. A vulnerability was found in Zhong Bang CRMEB Java 1.3.4. It has been classified as critical. This affects an unknown part of the file /api/admin/system/store/order/list. The manipulation of the argument keywords leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-222261 was assigned to this vulnerability. NVD description · AI analysis pending | 7.2 | <1% | PoC |
| — | |
| CVE-2022-44343 | CRMEB 4.4.4 is vulnerable to Any File download. CRMEB 4.4.4 is vulnerable to Any File download. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2020-21394 | SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename parameter in SystemDatabackup.php. SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename parameter in SystemDatabackup.php. NVD description · AI analysis pending | 8.8 | 1% | PoC |
| — | |
| CVE-2020-21787 +1 in the same advisory: …21788 | CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php. CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php. NVD description · AI analysis pending | 9.8 group max | 2% | PoC |
| — | |
| CVE-2020-25466 | A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrar A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — |