tag
Espocrm
Critical
EspoCRM Authenticated RCE via Formula ACL Bypass + Attachment Path Traversal — CVE-2026-33656
CVE-2026-33656·
EspoCRM <= 9.3.3
unpatched
Medium
EspoCRM 9.3.3 Stored HTML Injection in Email Notifications — CVE-2026-33657
CVE-2026-33657·
EspoCRM 9.3.3
patched
Medium
EspoCRM 9.3.3 Authenticated SSRF via Alternative IPv4 Loopback Notation — CVE-2026-33534
CVE-2026-33534·
EspoCRM 9.3.3
patched