Small CRM
PHPGurukul- Product type
- Software application
- Catalog vulnerabilities
- 14
Severity across 14 analyzed records
Verify to analyze this security profile
en
Severity across 14 analyzed records
Verify to analyze this security profile
As of 09/16/2026, within CyStack's analyzed data, Small CRM has 1 security vulnerability published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Small CRM and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-90575PHPGurukul Small CRM Login Success login.php unserialize deserialization | Exploitation statusPublic exploit | FixNot confirmed | Published09/13/2026 | SeverityMedium |
CVE-2025-15390PHPGurukul Small CRM edit-user.php authorization | Exploitation statusPublic exploit | FixNot confirmed | Published12/31/2025 | SeverityMedium |
CVE-2025-11053PHPGurukul Small CRM forgot-password.php sql injection | Exploitation statusPublic exploit | FixNot confirmed | Published09/27/2025 | SeverityMedium |
CVE-2025-10664PHPGurukul Small CRM create-ticket.php sql injection | Exploitation statusPublic exploit | FixNot confirmed | Published09/18/2025 | SeverityMedium |
CVE-2025-10114PHPGurukul Small CRM profile.php sql injection | Exploitation statusPublic exploit | FixNot confirmed | Published09/09/2025 | SeverityMedium |
CVE-2025-10079PHPGurukul Small CRM get-quote.php sql injection | Exploitation statusPublic exploit | FixNot confirmed | Published09/08/2025 | SeverityMedium |
CVE-2025-9834PHPGurukul Small CRM registration.php cross site scripting | Exploitation statusPublic exploit | FixNot confirmed | Published09/02/2025 | SeverityMedium |
CVE-2025-5227PHPGurukul Small CRM manage-tickets.php sql injection | Exploitation statusPublic exploit | FixNot confirmed | Published05/27/2025 | SeverityMedium |
CVE-2025-5226PHPGurukul Small CRM change-password.php sql injection | Exploitation statusPublic exploit | FixNot confirmed | Published05/27/2025 | SeverityMedium |
CVE-2024-13001PHPGurukul Small CRM index.php sql injection | Exploitation statusPublic exploit | FixNot confirmed | Published12/29/2024 | SeverityMedium |
CVE-2024-13000PHPGurukul Small CRM quote-details.php sql injection | Exploitation statusNot known exploited | FixNot confirmed | Published12/29/2024 | SeverityMedium |
CVE-2024-12999PHPGurukul Small CRM edit-user.php sql injection | Exploitation statusNot known exploited | FixNot confirmed | Published12/29/2024 | SeverityMedium |
CVE-2024-3691PHPGurukul Small CRM Registration Page sql injection | Exploitation statusPublic exploit | FixNot confirmed | Published04/12/2024 | SeverityHigh |
CVE-2024-3690PHPGurukul Small CRM Change Password sql injection | Exploitation statusPublic exploit | FixNot confirmed | Published04/12/2024 | SeverityMedium |